From 8f88fcedd601c0033b4469b66626a83011879baf Mon Sep 17 00:00:00 2001 From: Aldo Cortesi Date: Wed, 22 Jan 2014 13:33:02 +1300 Subject: Move the doc tree out into its own repo. --- doc-src/features/upstreamcerts.html | 21 --------------------- 1 file changed, 21 deletions(-) delete mode 100644 doc-src/features/upstreamcerts.html (limited to 'doc-src/features/upstreamcerts.html') diff --git a/doc-src/features/upstreamcerts.html b/doc-src/features/upstreamcerts.html deleted file mode 100644 index 8de75ee3..00000000 --- a/doc-src/features/upstreamcerts.html +++ /dev/null @@ -1,21 +0,0 @@ -When mitmproxy receives a connection destined for an SSL-protected service, it -freezes the connection before reading its request data, and makes a connection -to the upstream server to "sniff" the contents of its SSL certificate. The -information gained - the __Common Name__ and __Subject Alternative Names__ - is -then used to generate the interception certificate, which is sent to the client -so the connection can continue. - -This rather intricate little dance lets us seamlessly generate correct -certificates even if the client has specifed only an IP address rather than the -hostname. It also means that we don't need to sniff additional data to generate -certs in transparent mode. - -Upstream cert sniffing is on by default, and can optionally be turned off. - - - - - - - -
command-line --no-upstream-cert
-- cgit v1.2.3