SSL-проксі
Проксі, що обробляє SSL/TLS-зашифровані з’єднання - або тунелюючи їх без змін, або розшифровуючи й наново шифруючи для інспекції.
SSL-проксі обробляє SSL/TLS-зашифрований трафік - те саме шифрування за кожним https://-з’єднанням. У звичайному випадку SSL-проксі проводить зашифроване з’єднання наскрізь недоторканим (та сама поведінка, що в HTTPS-проксі через CONNECT), тож шифрування залишається з кінця в кінець між вашим клієнтом і ціллю.
Друге, окреме значення - SSL-перехоплення (або SSL-термінація), коли проксі розшифровує трафік, інспектує або змінює його, а потім наново шифрує перед пересиланням. Це використовують корпоративні шлюзи безпеки й зворотні проксі для фільтрації та кешування, але вимагає, щоб клієнт довіряв сертифікату проксі - інакше браузер попередить про загрозу безпеки.
Для користувачів проксі, зайнятих скрапінгом чи автоматизацією, «SSL-проксі» майже завжди означає перше: проксі, що коректно тунелює ваш HTTPS-трафік без порушення шифрування. Терміни SSL-проксі, HTTPS-проксі та HTTP-проксі з CONNECT багато в чому перетинаються в комерційних пропозиціях.
Ключовий момент: правильно поводжуваний SSL-проксі не послаблює ваше шифрування - ваша TLS-сесія узгоджується напряму з ціллю. Лише перехоплюючі проксі (які ви навмисно налаштовуєте й яким довіряєте) перебувають усередині зашифрованого каналу.
A marketing term with two meanings
Most providers use SSL proxy to mean a proxy that supports HTTPS traffic, which today is every proxy worth buying. In that sense the term carries no information: HTTPS goes through a CONNECT tunnel and the proxy handles it without seeing the contents.
The second meaning is the technical one: a proxy that terminates TLS itself, decrypts the traffic, inspects or modifies it, and re-encrypts it towards the destination. This requires the client to trust a certificate the proxy presents, which is why it exists inside corporate networks and not as a retail product.
SSL itself has been deprecated for years. Everything in current use is TLS, and the name persists out of habit rather than accuracy.
What ours do
We tunnel HTTPS without touching it. Nothing we run terminates your TLS:
What we see and what we do not
We see the hostname in CONNECT, timing, byte counts
We do not the request path, headers, body, or response
curl -x http://login:password@proxy.sotaproxy.com:10000 https://example.com- If a provider advertises SSL inspection or content modification, that is a different product with different privacy properties. Ours is a tunnel.
- Certificate warnings while using our proxies point at interception elsewhere on your network, or at a client configured to trust a corporate root.
- Disabling certificate verification to make an error go away usually hides a 407 rather than solving anything.
- The hostname is visible in the CONNECT line by design. Anyone promising otherwise for a standard HTTP proxy is describing something they do not have.
SSL proxy confusions
It does not mean more secure
Your security comes from TLS between your client and the site, which is present either way.
SSL and TLS are used interchangeably in marketing
SSL is obsolete. Everything current is TLS, whatever the product page says.
Interception is not a feature you want
In a retail proxy it would mean the operator can read your traffic.
It is not related to certificate errors you see
Those come from your client's trust store or from a middlebox on your network.
Пов'язані терміни
Дивись на практиці
Готовий використовувати ssl-проксі?
SotaProxy надає доступ до ротуючих резидентських, мобільних, дата-центр та ISP проксі. Без мінімальних платежів.
Почати