Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
encrypt connection between squid+browser w/ ssl - possible?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
DawgG
l33t
l33t


Joined: 17 Sep 2003
Posts: 874

PostPosted: Wed Dec 10, 2008 12:48 pm    Post subject: encrypt connection between squid+browser w/ ssl - possible? Reply with quote

my employer wants to set up a (semi)public wlan with web-access thru our proxy. i'm worried about security because (with wlan-encryption and all) it will still be possible for clients on the same network segment so sniff all the traffic. with http basically everything is sent in cleartext and on their own computers ppl can just run about any software they like.
i am wondering if it is possible to set up an additional proxy (squid) that uses our standard proxy as parent and encrypts its connections to the wlan-clients with https (for a reverse proxy with a "parent" webserver ist possible, but the client browsers send https-requests to the "pre-proxy's" https-port)
i am almost positive it will not work because the client browsers send plain http-reqs to the "pre-proxy's" https-port which it cannot understand - maybe someone can teach me sth else.

installation of additional software on the clients is not an option; except - maybe - a firefox add-on or sth.
i know the way to go would be ipsec, but tha's not an option, either.

(i know that the users are responsible themselves for what they send over http in a public wlan, but i think it's just better to offer a safe solution to them)
_________________
DUMM KLICKT GUT.
Back to top
View user's profile Send private message
GNUtoo
Veteran
Veteran


Joined: 05 May 2005
Posts: 1919

PostPosted: Fri Dec 12, 2008 4:48 pm    Post subject: Reply with quote

mabe openvpn is a better idea
Back to top
View user's profile Send private message
manaka
Apprentice
Apprentice


Joined: 23 Jul 2007
Posts: 178
Location: Spain

PostPosted: Fri Dec 12, 2008 10:32 pm    Post subject: Reply with quote

Have a look at PHProxy (http://sourceforge.net/projects/poxy/). And this Firefox plugin: https://addons.mozilla.org/en-US/firefox/addon/3239.

Not the best solution. But probably the one that requires the minimum client reconfiguration.
_________________
Javier Miqueleiz

"Listen to your heart. It knows all things, because it came from the Soul of the World, and it will one day return there."
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum