{"id":2591,"date":"2010-03-05T17:59:23","date_gmt":"2010-03-05T16:59:23","guid":{"rendered":"http:\/\/www.it-training-grote.de\/blog\/?p=2591"},"modified":"2010-03-05T17:59:23","modified_gmt":"2010-03-05T16:59:23","slug":"https-inspection-in-forefront-tmg-und-ip-ausnahmen","status":"publish","type":"post","link":"https:\/\/www.it-consulting-grote.de\/blog\/?p=2591","title":{"rendered":"HTTPS Inspection in Forefront TMG und IP-Ausnahmen"},"content":{"rendered":"<p>Hallo Leutz,<\/p>\n<p>Forefront TMG bietet eine ausgehende HTTPS-Ueberpruefung. Es koennen URL Ausnahmen konfiguriert werden. Wie ist das aber, wenn man nur die IP-Adressen als Ausnahmen konfigurieren moechte? Konkretes Beispiel war die Frage eines Besucher an meinem Stand, wie er Elster von der HTTPS-Ueberpruefung ausschliessen kann, da hier wohl nur IP-Adressen bekannt sind. In den Ausnahmen kann man ja nur URL-Sets konfigurieren, also sind IP-Adressen nicht zulaessig. Eine Antwort hatte ich nicht parat, ausser das DNS umzubiegen und mit gefakten DNS Name Mappings zu arbeiten.<\/p>\n<p>Also kurzerhand die Frage an Experten gestellt \ud83d\ude42 und kurze Zeit spaeter kam die Antwort von Jim Harrison:<\/p>\n<p class=\"MsoNormal\" style=\"margin: 0cm 0cm 0pt;\"><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; color: black; font-size: 10pt; mso-fareast-font-family: &quot;Times New Roman&quot;;\">&#8220;No, but if you know the certificate subject and SAN names used by those services, you can enter those in the exceptions.<\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin: 0cm 0cm 0pt;\"><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; color: black; font-size: 10pt; mso-fareast-font-family: &quot;Times New Roman&quot;;\">TMG uses the subject and SAN attributes to determine if the upstream server is &#8220;exceptional&#8221; as well as how to build the spoof cert if it needs to.<\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin: 0cm 0cm 0pt;\"><span style=\"font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;; color: black; font-size: 10pt; mso-fareast-font-family: &quot;Times New Roman&quot;;\">The primary reason IPs aren&#8217;t usable is that in the hosted cloud Internet of today, IP addresses do not represent anything even remotely like &#8220;identity&#8221; and identity is exactly the context in which certificate validation operates.&#8221;<\/span><\/p>\n<p class=\"MsoNormal\" style=\"margin: 0cm 0cm 0pt;\">\u00a0<\/p>\n<p class=\"MsoNormal\" style=\"margin: 0cm 0cm 0pt;\">\u00a0Gruss Marc<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hallo Leutz, Forefront TMG bietet eine ausgehende HTTPS-Ueberpruefung. Es koennen URL Ausnahmen konfiguriert werden. Wie ist das aber, wenn man nur die IP-Adressen als Ausnahmen konfigurieren moechte? Konkretes Beispiel war die Frage eines Besucher an meinem Stand, wie er Elster &hellip; <a href=\"https:\/\/www.it-consulting-grote.de\/blog\/?p=2591\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[8,5,46,10,3],"tags":[],"_links":{"self":[{"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2591"}],"collection":[{"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2591"}],"version-history":[{"count":4,"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2591\/revisions"}],"predecessor-version":[{"id":2907,"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=\/wp\/v2\/posts\/2591\/revisions\/2907"}],"wp:attachment":[{"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.it-consulting-grote.de\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}