From: Bill Ricker <bill.n1vux at>
>> The downside of this latter approach is that the IT org can then sign
>> certs for *ANY* other site and therefore intercept all HTTPS traffic
>> they wish to see.
> If the IT / SEC group is competent to do the one, they're probably already
> doing the other!
> (And possibly consider themselves legally required to, to prevent
> exfiltration of sensitive data -- HIPAA, SARBOX, ...)

It's a known thing ... you can buy hardware accelerators that terminate
HTTPS connections from clients and dynamically generate certs for any
host name.


BLU is a member of BostonUserGroups
Boston Linux & Unix