|
|
|
|
|
by tialaramex
3105 days ago
|
|
"most TLS libraries" is vague. Microsoft and Apple each include one with their OS. The Microsoft one definitely accepts total garbage as a valid CA root. I know because my employer pushed such a root to enable their MitM proxy and it worked fine... in Windows (and thus IE/ Edge). They had to replace it because Firefox and other systems threw a fit. I'm happy to be proved wrong about this, but my experience tells me "most TLS libraries" is misleading even if technically true. |
|
In fact it appears they did exactly the right thing to get https working correctly in their mixed-mode (localhost + outside world) environment.