<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.edge.arista.com/index.php?action=history&amp;feed=atom&amp;title=HTTPS</id>
	<title>HTTPS - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.edge.arista.com/index.php?action=history&amp;feed=atom&amp;title=HTTPS"/>
	<link rel="alternate" type="text/html" href="https://wiki.edge.arista.com/index.php?title=HTTPS&amp;action=history"/>
	<updated>2026-04-04T06:21:49Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.3</generator>
	<entry>
		<id>https://wiki.edge.arista.com/index.php?title=HTTPS&amp;diff=20969&amp;oldid=prev</id>
		<title>Dmorris at 15:57, 12 November 2017</title>
		<link rel="alternate" type="text/html" href="https://wiki.edge.arista.com/index.php?title=HTTPS&amp;diff=20969&amp;oldid=prev"/>
		<updated>2017-11-12T15:57:21Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 15:57, 12 November 2017&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l18&quot;&gt;Line 18:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 18:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Options that rely on modifying the stream will not work (Youtube for Schools, Safe-Search enforcement).&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Options that rely on modifying the stream will not work (Youtube for Schools, Safe-Search enforcement).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* The URI &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;of the request &lt;/del&gt;is encrypted so only the domain is known. This means sites will be either blocked or not which may be undesirable for some sites (like Wikipedia) where you want to allow some content but not other content.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* The URI &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;and content &lt;/ins&gt;is encrypted so only the domain is known. This means sites will be either blocked or not which may be undesirable for some sites (like Wikipedia) where you want to allow some content but not other content.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* HTTPS block pages will display an certificate warning if the client does not have Untangle&amp;#039;s root CA cert installed.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* HTTPS block pages will display an certificate warning if the client does not have Untangle&amp;#039;s root CA cert installed.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Dmorris</name></author>
	</entry>
	<entry>
		<id>https://wiki.edge.arista.com/index.php?title=HTTPS&amp;diff=3671&amp;oldid=prev</id>
		<title>Dmorris at 08:16, 15 February 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.edge.arista.com/index.php?title=HTTPS&amp;diff=3671&amp;oldid=prev"/>
		<updated>2016-02-15T08:16:52Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;HTTPS is HTTP over SSL. Untangle applications (like [[Web Filter]]) will typically filter web request by reading them transparently as they are sent to the server. The applications are free to block requests, modify them, redirect them to other places and other actions.&lt;br /&gt;
&lt;br /&gt;
HTTPS, however, is much more difficult because it is encrypted between the client and the server. Because Untangle sits in between the client and the server, all it sees is an encrypted stream. It is unable to see the web request or modify it.&lt;br /&gt;
&lt;br /&gt;
Because of this, dealing with HTTPS properly requires some extra steps. Untangle provides a few ways to deal with HTTPS. Choosing the right one depends on the goals and desires of your organization.&lt;br /&gt;
&lt;br /&gt;
= [[Web Filter]] without [[SSL Inspector]] =&lt;br /&gt;
&lt;br /&gt;
The first and most common way to deal with HTTPS is to enable the options in Web Filter that allow it categorize HTTPS sessions by &amp;quot;SNI&amp;quot; IP or cert information. Basically these options allow Web Filter to handle HTTPS without decrypting it. To read more about these options read [[Web_Filter#HTTPS_Options]].&lt;br /&gt;
&lt;br /&gt;
== Advantages ==&lt;br /&gt;
&lt;br /&gt;
* This technique is very simple to deploy and maintain. &lt;br /&gt;
* It requires no changes on the client. &lt;br /&gt;
* This technique is usually effective with blocking categories. &lt;br /&gt;
&lt;br /&gt;
== Disadvantages ==&lt;br /&gt;
&lt;br /&gt;
* Options that rely on modifying the stream will not work (Youtube for Schools, Safe-Search enforcement).&lt;br /&gt;
* The URI of the request is encrypted so only the domain is known. This means sites will be either blocked or not which may be undesirable for some sites (like Wikipedia) where you want to allow some content but not other content.&lt;br /&gt;
* HTTPS block pages will display an certificate warning if the client does not have Untangle&amp;#039;s root CA cert installed.&lt;br /&gt;
&lt;br /&gt;
= [[SSL Inspector]] full inspection =&lt;br /&gt;
&lt;br /&gt;
[[SSL Inspector]] decrypts HTTPS and re-encrypts it on the server side and maintains two separate encrypted channels. Between the two encrypted channel normal unencrypted HTTP flows through the other applications. SSL Inspector can do this task on all HTTPS traffic giving the admin full control over all HTTPS traffic.&lt;br /&gt;
&lt;br /&gt;
== Advantages ==&lt;br /&gt;
&lt;br /&gt;
* Very powerful.&lt;br /&gt;
* Full featured.&lt;br /&gt;
&lt;br /&gt;
== Disadvantages ==&lt;br /&gt;
&lt;br /&gt;
* Requires new root certificate to be added to all clients&amp;#039; browsers and O/S&amp;#039;s.&lt;br /&gt;
* May cause higher load if the server is processing heavy amounts of HTTPS traffic.&lt;br /&gt;
* May interfere with certain HTTPS apps with hardcoded certs and require &amp;quot;ignore rules&amp;quot; to be added.&lt;br /&gt;
* The administrator, not the user, is now responsible for deciding which upstream certificates are accepted in some cases (self-signed certs etc) and configuring these cases.&lt;br /&gt;
&lt;br /&gt;
= [[SSL Inspector]] partial inspection =&lt;br /&gt;
&lt;br /&gt;
Similar to above admins can use SSL Inspector on only important HTTPS traffic, like google.com, youtube.com, facebook.com, etc while handling other HTTPS traffic as encrypted channels. This is similar to the above but slightly less maintenance overhead because only certain HTTPS sites are effected.&lt;br /&gt;
&lt;br /&gt;
== Advantages ==&lt;br /&gt;
&lt;br /&gt;
* Very powerful&lt;br /&gt;
* Most features (Safe Search enforcement, logging of searches, etc) still work.&lt;br /&gt;
* Doesn&amp;#039;t touch critical HTTPS to banks and other applications.&lt;br /&gt;
&lt;br /&gt;
== Disadvantages ==&lt;br /&gt;
&lt;br /&gt;
* Requires new root certificate to be added to all clients&amp;#039; browsers and O/S&amp;#039;s for monitored sites.&lt;br /&gt;
* May cause higher load if lots of HTTPS traffic.&lt;/div&gt;</summary>
		<author><name>Dmorris</name></author>
	</entry>
</feed>