aboutsummaryrefslogtreecommitdiffstats
path: root/docs/features/upstreamcerts.rst
diff options
context:
space:
mode:
Diffstat (limited to 'docs/features/upstreamcerts.rst')
-rw-r--r--docs/features/upstreamcerts.rst23
1 files changed, 0 insertions, 23 deletions
diff --git a/docs/features/upstreamcerts.rst b/docs/features/upstreamcerts.rst
deleted file mode 100644
index af2e2226..00000000
--- a/docs/features/upstreamcerts.rst
+++ /dev/null
@@ -1,23 +0,0 @@
-.. _upstreamcerts:
-
-Upstream Certificates
-=====================
-
-When mitmproxy receives a connection destined for an SSL-protected service, it
-freezes the connection before reading its request data, and makes a connection
-to the upstream server to "sniff" the contents of its SSL certificate. The
-information gained - the **Common Name** and **Subject Alternative Names** - is
-then used to generate the interception certificate, which is sent to the client
-so the connection can continue.
-
-This rather intricate little dance lets us seamlessly generate correct
-certificates even if the client has specified only an IP address rather than the
-hostname. It also means that we don't need to sniff additional data to generate
-certs in transparent mode.
-
-Upstream cert sniffing is on by default, and can optionally be turned off.
-
-================== =============================
-command-line :option:`--no-upstream-cert`
-mitmproxy shortcut :kbd:`o` then :kbd:`U`
-================== =============================