我自己是覺得沒事不要找自己麻煩會比較好,可以的話請客戶先用Categorize https sites試試看,就沒有灑憑證的問題,效果還不錯,只是有些企業彼此之間Intranet的站台要手動開白名單。
如果怕https inspection有誤判行為,可以用以下參數測試:
Enhanced HTTPS Inspection Bypass
1. In the $FWDIR/boot/modules/fwkern.conf file on the gateway, add:
enhanced_ssl_inspection=1
2. Reboot.
Enhanced HTTPS Inspection Bypass lets the gateway bypass traffic to servers that require client certificate authentication and bypass non-browser applications.
特別像SSL pinning一類的東西應該可以解掉。
HTTPS inspection開下去會多很多Troubleshooting的功,何況我們都在客戶端POC時吃過虧,實在是不建議。