{"id":38110,"date":"2019-10-31T22:21:42","date_gmt":"2019-10-31T19:21:42","guid":{"rendered":"https:\/\/prohoster.info\/blog\/dpi-inspektsiya-ssl-protivorechit-smyslu-kriptografii-no-kompanii-eyo-vnedryayut\/"},"modified":"2019-10-31T22:21:42","modified_gmt":"2019-10-31T19:21:42","slug":"dpi-inspektsiya-ssl-protivorechit-smyslu-kriptografii-no-kompanii-eyo-vnedryayut","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/dpi-inspektsiya-ssl-protivorechit-smyslu-kriptografii-no-kompanii-eyo-vnedryayut","title":{"rendered":"DPI (SSL inspection) contradicts the essence of cryptography, yet companies are implementing it","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"DPI (SSL inspection) contradicts the essence of cryptography, yet companies are implementing it\" src=\"\/wp-content\/uploads\/2019\/09\/78d42fdffe3574791305bb29b471692f.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Chain of Trust. CC BY-SA 4.0 <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.m.wikipedia.org\/wiki\/%D0%A4%D0%B0%D0%B9%D0%BB:Chain_of_trust_ru.svg\">Yanpas<\/a><\/noindex><\/i><\/p>\n<p>SSL Traffic Inspection (SSL\/TLS decryption, SSL analysis or DPI) is becoming an increasingly hot topic in the corporate sector. The idea of decrypting traffic seems to contradict the very concept of cryptography. However, the fact is that more and more companies are using DPI technologies, explaining it as a necessity for checking content for malware, data leaks, etc.<\/p>\n<p>Well, if we accept as a fact that such a technology needs to be implemented, we should at least consider ways to do it in the safest and most manageable way. At the very least, we shouldn\u2019t rely on those certificates provided by the DPI system vendor.<\/p>\n<p>There is one aspect of implementation that not everyone is aware of. In fact, many are truly surprised when they hear about it. This is a private certificate authority (CA). It generates certificates for decrypting and re-encrypting traffic.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nInstead of relying on self-signed certificates or certificates from DPI devices, you can use a dedicated CA from a third-party certificate authority, such as GlobalSign. But first, let's take a brief overview of the problem itself.<\/p>\n<h2>What is SSL inspection and why is it used?<\/h2>\n<p>\nAn increasing number of public websites are transitioning to HTTPS. For example, according to <noindex><a rel=\"nofollow\" href=\"https:\/\/transparencyreport.google.com\/https\/overview?hl=en\">Chrome statistics<\/a><\/noindex>, at the beginning of September 2019, the share of encrypted traffic in Russia reached 83%.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/to\/2a\/i0\/to2ai0j5kawt2uhmd6siugk9zge.png\"><img decoding=\"async\" alt=\"DPI (SSL inspection) contradicts the essence of cryptography, yet companies are implementing it\" src=\"\/wp-content\/uploads\/2019\/09\/db06cb3b7bba7f64b65135e77f58e6ee.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>Unfortunately, traffic encryption is increasingly being used by malicious actors, especially since Let's Encrypt distributes thousands of free SSL certificates automatically. As a result, HTTPS is used everywhere \u2014 and the padlock in the browser's address bar is no longer a reliable indicator of security.<\/p>\n<p>From these positions, DPI solution manufacturers promote their product. They are implemented between end-users (i.e., your employees browsing the web) and the Internet, filtering out malicious traffic. Today, there are a number of such products available in the market, but the processes are essentially the same. HTTPS traffic goes through a checking device, where it is decrypted and checked for malware.<\/p>\n<p>After the verification is completed, the device creates a new SSL session with the end client for decrypting and re-encrypting content.<\/p>\n<h2>How the decryption\/re-encryption process works<\/h2>\n<p>\nFor the SSL inspection device to decrypt and re-encrypt packets before sending them to end users, it must be able to issue SSL certificates on the fly. This means that a trusted CA certificate must be installed on it.<\/p>\n<p>It is crucial for the company (or any middleman) that these SSL certificates are trusted in browsers (i.e., do not trigger alarming warning messages like the one below). Therefore, the CA chain (or hierarchy) must be present in the browser's trust store. Since these certificates are not issued by public trusted certificate authorities, it is necessary to manually distribute the CA hierarchies to all end clients.<\/p>\n<p><img decoding=\"async\" alt=\"DPI (SSL inspection) contradicts the essence of cryptography, yet companies are implementing it\" src=\"\/wp-content\/uploads\/2019\/09\/421a6ac078656d499736d273b39ab792.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Warning message for a self-signed certificate in Chrome. Source: <noindex><a rel=\"nofollow\" href=\"https:\/\/self-signed.badssl.com\/\">BadSSL.com<\/a><\/noindex><\/i><\/p>\n<p>On Windows computers, Active Directory and group policies can be utilized, but the process is more complex for mobile devices.<\/p>\n<p>The situation is further complicated if there is a need to support other root certificates in a corporate environment, such as those from Microsoft or based on OpenSSL. Additionally, the protection and management of private keys is essential to ensure that none of the keys expire unexpectedly.<\/p>\n<h2>The best option is to have a private, dedicated root certificate from a third-party CA.<\/h2>\n<p>\nIf managing multiple roots or self-signed certificates is not appealing, there is another option: you can rely on a third-party CA. In this case, the certificates are issued from <b>a private<\/b> certification authority, which is linked in the trust chain with a dedicated, private root certificate authority created specifically for the company.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/hh\/ss\/vn\/hhssvnz46qs34htk1iotowv_viy.png\"><img decoding=\"async\" alt=\"DPI (SSL inspection) contradicts the essence of cryptography, yet companies are implementing it\" src=\"\/wp-content\/uploads\/2019\/09\/681cd82435b9e275b858a66fddaf3cf3.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><br \/>\n<i>Simplified architecture for dedicated client root certificates.<\/i><\/p>\n<p>This configuration alleviates some of the issues mentioned earlier: it at least reduces the number of roots to manage. Here, one private root CA can be used for all internal PKI needs, along with any number of intermediate CAs. For example, the diagram above shows a multi-tier hierarchy where one of the intermediate CAs is used for SSL validation\/decryption, while another is for internal computers (laptops, servers, desktops, etc.).<\/p>\n<p>In this scheme, there is no need to host the CA on all clients because the top-level CA is hosted at GlobalSign, which resolves issues related to securing the private key and its validity period.<\/p>\n<p>Another advantage of this approach is the ability to revoke the SSL inspection CA for any reason. Instead, a new CA is simply created, bound to your original private root, and can be used immediately.<\/p>\n<p>Despite the controversies, businesses are increasingly implementing SSL traffic inspection as part of internal or private PKI infrastructure. Other use cases of private PKI include issuing certificates for device or user authentication, SSL for internal servers, and various configurations that are not permitted in public trusted certificates according to CA\/Browser Forum requirements.<\/p>\n<h2>Browsers resist<\/h2>\n<p>\nIt should be noted that browser developers are trying to counter this trend and protect end users from MiTM. For example, just a few days ago, Mozilla <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.mozilla.org\/futurereleases\/2019\/09\/06\/whats-next-in-making-dns-over-https-the-default\/\">made the decision<\/a><\/noindex> to enable the DoH (DNS-over-HTTPS) protocol by default in one of the upcoming versions of the Firefox browser. The DoH protocol hides DNS queries from DPI systems, making SSL inspection more difficult.<\/p>\n<p>On similar plans, on September 10, 2019, <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.chromium.org\/2019\/09\/experimenting-with-same-provider-dns.html\">announced<\/a><\/noindex> Google announced for the Chrome browser.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/clck.ru\/HwY9L\"><img decoding=\"async\" alt=\"DPI (SSL inspection) contradicts the essence of cryptography, yet companies are implementing it\" src=\"\/wp-content\/uploads\/2019\/09\/d39cdcbea0035dc1d0edc01b74210964.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p class=\"for_users_only_msg\">Only registered users can participate in the survey. <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/auth\/login\/\">Please log in<\/a><\/noindex>, please.<\/p>\n<h2 class=\"default-block__polling-title\">Do you think the company has the right to inspect its employees' SSL traffic?<\/h2>\n<ul class=\"content-list content-list_polling\">\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    Yes, with their consent<\/p>\n<\/li>\n<li class=\"content-list__item content-list__item_polling\">\n<p>                    No, asking for such consent is illegal and\/or unethical<\/p>\n<\/li>\n<\/ul>\n<p>    122 users voted. 15 users abstained.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/globalsign\/blog\/467259\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0426\u0435\u043f\u043e\u0447\u043a\u0430 \u0434\u043e\u0432\u0435\u0440\u0438\u044f. CC BY-SA 4.0 Yanpas \u0418\u043d\u0441\u043f\u0435\u043a\u0446\u0438\u044f \u0442\u0440\u0430\u0444\u0438\u043a\u0430 SSL (\u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u043a\u0430 SSL\/TLS, \u0430\u043d\u0430\u043b\u0438\u0437 SSL \u0438\u043b\u0438 DPI) \u0441\u0442\u0430\u043d\u043e\u0432\u0438\u0442\u0441\u044f \u0432\u0441\u0435 \u0431\u043e\u043b\u0435\u0435 \u0433\u043e\u0440\u044f\u0447\u0435\u0439 \u0442\u0435\u043c\u043e\u0439 \u043e\u0431\u0441\u0443\u0436\u0434\u0435\u043d\u0438\u044f \u0432 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u043c \u0441\u0435\u043a\u0442\u043e\u0440\u0435. \u0418\u0434\u0435\u044f \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u043e\u0432\u043a\u0438 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432\u0440\u043e\u0434\u0435 \u0431\u044b \u043f\u0440\u043e\u0442\u0438\u0432\u043e\u0440\u0435\u0447\u0438\u0442 \u0441\u0430\u043c\u043e\u0439 \u043a\u043e\u043d\u0446\u0435\u043f\u0446\u0438\u0438 \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0438. \u041e\u0434\u043d\u0430\u043a\u043e \u0444\u0430\u043a\u0442 \u0435\u0441\u0442\u044c \u0444\u0430\u043a\u0442: \u0432\u0441\u0451 \u0431\u043e\u043b\u044c\u0448\u0435 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 DPI, \u043e\u0431\u044a\u044f\u0441\u043d\u044f\u044f \u044d\u0442\u043e \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u043d\u0442\u0430 \u043d\u0430 \u043f\u0440\u0435\u0434\u043c\u0435\u0442 \u0437\u043b\u043e\u0432\u0440\u0435\u0434\u043e\u0432, \u0443\u0442\u0435\u0447\u0435\u043a \u0434\u0430\u043d\u043d\u044b\u0445 \u0438 \u0442. [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":28610,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-38110","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0426\u0435\u043f\u043e\u0447\u043a\u0430 \u0434\u043e\u0432\u0435\u0440\u0438\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/dpi-inspektsiya-ssl-protivorechit-smyslu-kriptografii-no-kompanii-eyo-vnedryayut\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47DPI (\u0438\u043d\u0441\u043f\u0435\u043a\u0446\u0438\u044f SSL) \u043f\u0440\u043e\u0442\u0438\u0432\u043e\u0440\u0435\u0447\u0438\u0442 \u0441\u043c\u044b\u0441\u043b\u0443 \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0438, \u043d\u043e \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0435\u0451 \u0432\u043d\u0435\u0434\u0440\u044f\u044e\u0442 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0426\u0435\u043f\u043e\u0447\u043a\u0430 \u0434\u043e\u0432\u0435\u0440\u0438\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/dpi-inspektsiya-ssl-protivorechit-smyslu-kriptografii-no-kompanii-eyo-vnedryayut\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:21:42+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:21:42+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47DPI (SSL inspection) contradicts the purpose of cryptography, yet companies are implementing it | ProHoster","description":"Chain of trust.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/dpi-inspektsiya-ssl-protivorechit-smyslu-kriptografii-no-kompanii-eyo-vnedryayut","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47DPI (\u0438\u043d\u0441\u043f\u0435\u043a\u0446\u0438\u044f SSL) \u043f\u0440\u043e\u0442\u0438\u0432\u043e\u0440\u0435\u0447\u0438\u0442 \u0441\u043c\u044b\u0441\u043b\u0443 \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0438, \u043d\u043e \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 \u0435\u0451 \u0432\u043d\u0435\u0434\u0440\u044f\u044e\u0442 | ProHoster","og:description":"\u0426\u0435\u043f\u043e\u0447\u043a\u0430 \u0434\u043e\u0432\u0435\u0440\u0438\u044f.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/dpi-inspektsiya-ssl-protivorechit-smyslu-kriptografii-no-kompanii-eyo-vnedryayut","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:21:42+00:00","article:modified_time":"2019-10-31T19:21:42+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38110","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 20:30:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:15:22","updated":"2026-01-23 20:30:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38110"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38110\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/28610"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}