cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
207
Views
0
Helpful
3
Replies

Disable HTTPS

Brian Bergin
Level 4
Level 4

Is it possible to disable HTTPS when accessed from the local subnet?  On a local LAN if an admin needs to worry about their employees snooping on LAN traffic they have bigger problems than what's garnered from FindIT information.  The whining that every browser gives when connecting to a local HTTPS site with a self-signed cert is just a pain and there's zero reason to pay for one and the hassle of creating and administering local certs isn't worth it either.

3 Replies 3

David Harper
Cisco Employee
Cisco Employee

That's a fair point, but I do think turning HTTP on would be a short term solution, given the stated plans from the browser vendors to start raising red flags on HTTP sites generally.  My thought was to try and address the certificate problem in a user-friendly manner, potentially by integrating the letsencrypt agent, which would allow something very close to 'click a button for a free, browser recognised certificate'.  How would that grab you as a solution for this?

Cheers,

Dave.

I'm good with letsencrypt, the problem is you have to renew that constantly.  They're not long-term certs.  Maybe if you automate the process so it renews it ever 90 days or whatever they require.

It would definitely need to be automated.  It's not workable any other way.  In any case, they have designed the service to be automated for exactly that reason, so I don't expect any serious issues getting it to work.

Cheers,

Dave.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: