|
|
|
|
|
by closeparen
3419 days ago
|
|
>The MITM proxy cannot present the client certificate to the server, since it doesn't have the corresponding private key. The MITM proxy is operated by the same department that has root on all the endpoints it's intercepting. If necessary, the "endpoint protection" product will grab the private key, or just scrape the details of the browser session from the browser's memory rather than at network level. |
|