Proxy SSL
Un proxy que maneja conexiones cifradas SSL/TLS, ya sea tunelizándolas intactas o terminándolas y volviéndolas a cifrar para su inspección.
Un proxy SSL maneja el tráfico cifrado SSL/TLS - el cifrado detrás de cada conexión https://. En el caso común, un proxy SSL tuneliza la conexión cifrada intacta (el mismo comportamiento que un proxy HTTPS con CONNECT), de modo que el cifrado permanece de extremo a extremo entre tu cliente y el destino.
Un segundo significado distinto es la interceptación SSL (o terminación SSL), donde el proxy descifra el tráfico, lo inspecciona o modifica, y luego lo vuelve a cifrar antes de reenviarlo. Lo usan las pasarelas de seguridad corporativas y los proxies inversos para filtrado y caché, pero requiere que el cliente confíe en el certificado del proxy - de lo contrario, el navegador advierte de un riesgo de seguridad.
Para los usuarios de proxies que hacen scraping o automatización, "proxy SSL" casi siempre significa lo primero: un proxy que tuneliza correctamente tu tráfico HTTPS sin romper el cifrado. Los términos proxy SSL, proxy HTTPS y proxy HTTP con CONNECT se solapan en gran medida en las ofertas comerciales.
El punto clave es que un proxy SSL que se comporta correctamente no debilita tu cifrado - tu sesión TLS se negocia directamente con el destino. Solo los proxies de interceptación (que configurarías y en los que confiarías deliberadamente) se sitúan dentro del canal cifrado.
A marketing term with two meanings
Most providers use SSL proxy to mean a proxy that supports HTTPS traffic, which today is every proxy worth buying. In that sense the term carries no information: HTTPS goes through a CONNECT tunnel and the proxy handles it without seeing the contents.
The second meaning is the technical one: a proxy that terminates TLS itself, decrypts the traffic, inspects or modifies it, and re-encrypts it towards the destination. This requires the client to trust a certificate the proxy presents, which is why it exists inside corporate networks and not as a retail product.
SSL itself has been deprecated for years. Everything in current use is TLS, and the name persists out of habit rather than accuracy.
What ours do
We tunnel HTTPS without touching it. Nothing we run terminates your TLS:
What we see and what we do not
We see the hostname in CONNECT, timing, byte counts
We do not the request path, headers, body, or response
curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com- If a provider advertises SSL inspection or content modification, that is a different product with different privacy properties. Ours is a tunnel.
- Certificate warnings while using our proxies point at interception elsewhere on your network, or at a client configured to trust a corporate root.
- Disabling certificate verification to make an error go away usually hides a 407 rather than solving anything.
- The hostname is visible in the CONNECT line by design. Anyone promising otherwise for a standard HTTP proxy is describing something they do not have.
SSL proxy confusions
It does not mean more secure
Your security comes from TLS between your client and the site, which is present either way.
SSL and TLS are used interchangeably in marketing
SSL is obsolete. Everything current is TLS, whatever the product page says.
Interception is not a feature you want
In a retail proxy it would mean the operator can read your traffic.
It is not related to certificate errors you see
Those come from your client's trust store or from a middlebox on your network.
Términos relacionados
Ver esto en práctica
¿Listo para usar proxy ssl?
SotaProxy te da acceso a proxies residenciales rotativos, móviles, de centro de datos e ISP. Sin compromiso mínimo.
Empezar