Post Reply 
certs.pem (certs120102.zip)
Jan. 05, 2012, 05:31 AM
Post: #13
RE: certs.pem (certs120102.zip)
ReadMe.txt Wrote:NEW: Proxomitron now can check to make sure the certificate on the
remote server is valid. It looks for a file named "certs.pem" in
the Proxomitron base folder. If found, this file should contain
a list of trusted certificate authorities in the PEM format used
by OpenSSL.

"If found", so after you removed "certs.pem" the Proxomitron simply decrypted the data. No attempt was made to validate the certificate.

ReadMe.txt Wrote:Proxomitron will pop-up it's own certificate warning dialog if
the SSL site's certificate has problems or can't be matched to
one of the trusted certificates on file.

So far, I've removed two certificates that generated errors (and am seeing errors related to other "new" certificates). I'm assuming that the remaining certificates get the job done correctly.
A guess is that some of the new certificates indicate abilities that the Proxomitron does not have.

Current "new" errors are of the "Certificate's host name (CN) doesn't match the site's" or the CN contains a wildcard variety, http://www.torproject.org or http://www.hsn.com .

I would rather people use a "certs.pem" and

ReadMe.txt Wrote:Keep in mind certificates are just used to help insure your actually
connecting to the site you think you are and not some "spoofed" site.
Whether they actually do this or not is debatable. Many sites (especially
smaller ones) may not be using properly "signed" certificates, but this
doesn't mean your connection is not as encrypted. Really all it means is
they didn't cough up some money for VeriSign's official stamp of approval.
Likewise, a valid certificate is no guarantee a site won't rip you off -
you must still be careful before trusting a site with sensitive data.

Still, that being said, it's always safer to connect in pass-thru mode
(see below) in cases where security is critical

HTH
Add Thank You Quote this message in a reply
Post Reply 


Messages In This Thread
certs.pem (certs120102.zip) - JJoe - Dec. 29, 2010, 09:29 PM
RE: certs.pem (certs101229.zip) - ProxRocks - Dec. 29, 2010, 11:10 PM
RE: certs.pem (certs101229.zip) - sbk - Sep. 29, 2011, 03:49 PM
RE: certs.pem (certs101229.zip) - JJoe - Sep. 30, 2011, 03:19 AM
RE: certs.pem (certs101229.zip) - ProxRocks - Jan. 01, 2012, 11:23 PM
RE: certs.pem (certs101229.zip) - JJoe - Jan. 02, 2012, 05:17 AM
RE: certs.pem (certs101229.zip) - JJoe - Jan. 02, 2012, 08:45 PM
RE: certs.pem (certs120102.zip) - ProxRocks - Jan. 02, 2012, 10:11 PM
RE: certs.pem (certs120102.zip) - ProxRocks - Jan. 02, 2012, 10:42 PM
RE: certs.pem (certs120102.zip) - ProxRocks - Jan. 03, 2012, 05:33 PM
RE: certs.pem (certs120102.zip) - JJoe - Jan. 04, 2012, 09:56 PM
RE: certs.pem (certs120102.zip) - ProxRocks - Jan. 04, 2012, 11:12 PM
RE: certs.pem (certs120102.zip) - JJoe - Jan. 05, 2012, 05:44 AM
RE: certs.pem (certs120102.zip) - JJoe - Jan. 05, 2012 05:31 AM
RE: certs.pem (certs120102.zip) - ProxRocks - Jan. 05, 2012, 07:08 AM
RE: certs.pem (certs120102.zip) - sbk - Jan. 07, 2012, 06:20 AM
RE: certs.pem (certs120102.zip) - chatterer - Feb. 03, 2013, 11:46 AM
RE: certs.pem (certs120102.zip) - JJoe - Feb. 04, 2013, 02:02 AM
RE: certs.pem (certs120102.zip) - chatterer - Feb. 04, 2013, 04:35 AM
RE: certs.pem (certs120102.zip) - JJoe - Feb. 04, 2013, 04:48 AM
RE: certs.pem (certs120102.zip) - ProxRocks - Nov. 14, 2013, 02:32 PM
RE: certs.pem (certs120102.zip) - JJoe - Nov. 23, 2013, 10:09 PM
RE: certs.pem (certs120102.zip) - ProxRocks - Nov. 23, 2013, 10:38 PM
RE: certs.pem (certs120102.zip) - JJoe - Nov. 24, 2013, 01:32 AM
RE: certs.pem (certs120102.zip) - ProxRocks - Nov. 24, 2013, 01:37 PM
RE: certs.pem (certs120102.zip) - JJoe - Nov. 24, 2013, 07:31 PM
RE: certs.pem (certs120102.zip) - ProxRocks - Nov. 24, 2013, 08:21 PM
RE: certs.pem (certs120102.zip) - JJoe - Nov. 24, 2013, 08:49 PM
RE: certs.pem (certs120102.zip) - ProxRocks - Nov. 25, 2013, 09:14 AM

Forum Jump: