mirror of
https://github.com/sonertari/SSLproxy
synced 2024-11-18 03:25:31 +00:00
Document the limitations of passthrough mode (-P)
This commit is contained in:
parent
4f0a019d5a
commit
b8d8af7b29
11
sslsplit.1
11
sslsplit.1
@ -219,9 +219,14 @@ Passthrough SSL/TLS connections which cannot be split instead of dropping them.
|
||||
Connections cannot be split if \fB-c\fP and \fB-k\fP are not given and the
|
||||
site does not match any certificate loaded using \fB-t\fP, or if the connection
|
||||
to the original server gives SSL/TLS errors. Specifically, this happens if the
|
||||
site requests a client certificate. Passthrough with \fB-P\fP results in
|
||||
uninterrupted service for the clients, while dropping is the more secure
|
||||
alternative if unmonitored connections must be prevented.
|
||||
site requests a client certificate.
|
||||
In these situations, passthrough with \fB-P\fP results in uninterrupted service
|
||||
for the clients, while dropping is the more secure alternative if unmonitored
|
||||
connections must be prevented.
|
||||
Passthrough mode currently does not apply to SSL/TLS errors in the connection
|
||||
from the client, since the connection from the client cannot easily be retried.
|
||||
Specifically, \fB-P\fP does not currently work for clients that do not accept
|
||||
forged certificates.
|
||||
.TP
|
||||
.B \-r \fIproto\fP
|
||||
Force SSL/TLS protocol version on both client and server side to \fIproto\fP
|
||||
|
Loading…
Reference in New Issue
Block a user