New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Envoy forward proxy - man in the middle with ssl termination #20425
Comments
May be cluster filter or custom HTTP conn pool helps. 🤔 |
How? Care to elaborate? |
@soulxu maybe you know details. |
@batistado not sure you are asking a normal tls termination or something like what @LuyaoZhong is doing here #18928 |
@soulxu No we don't want to envoy to generate a copied cert from upstream service's cert (like www.google.com). My use case is this: Current setup: External service presents our org's self signed cert to internal service and internal service verifies it via our org's root CA cert. Want setup: We want to able to install our org's self signed cert and root CA to envoy so envoy can mimic External service to internal service and then to external service it behaves like internal service. |
@batistado I think it is indeed what we are doing with #18928 . We have a workable PR to mimic the server certificate, which might satisfy your requirement. There are limitations if we don't have the real server cert as reference to mimic cert, for instance we will lose TLS extensions, etc. That's why we are discussing the new workflow on #18928. |
This issue has been automatically marked as stale because it has not had activity in the last 30 days. It will be closed in the next 7 days unless it is tagged "help wanted" or "no stalebot" or other activity occurs. Thank you for your contributions. |
@LuyaoZhong I want to test your changes. So the traffic has to be routed to envoy via iptable rules or some other way, in your example config attached in PR? |
@vorishirne Yes, you need to route traffic to Envoy with proper iptables rule set. |
This issue has been automatically marked as stale because it has not had activity in the last 30 days. It will be closed in the next 7 days unless it is tagged "help wanted" or "no stalebot" or other activity occurs. Thank you for your contributions. |
@LuyaoZhong is this feature still under development |
@vorishirne Yes, see the issue TLS bumping . |
This issue has been automatically marked as stale because it has not had activity in the last 30 days. It will be closed in the next 7 days unless it is tagged "help wanted" or "no stalebot" or other activity occurs. Thank you for your contributions. |
This issue has been automatically closed because it has not had activity in the last 37 days. If this issue is still valid, please ping a maintainer and ask them to label it as "help wanted" or "no stalebot". Thank you for your contributions. |
This video could be useful? just watched it myself, looking for similar things https://www.youtube.com/watch?v=B8nTc08CeRQ |
Hi
I wanted to check if envoy supports Man in the middle with SSL termination as a forward proxy?
If so can you link me to any documentation or example config how to do it?
The text was updated successfully, but these errors were encountered: