Community discussions

MikroTik App
 
othmane
just joined
Topic Author
Posts: 8
Joined: Mon Apr 21, 2014 8:35 pm

https redirect issue

Mon Jul 07, 2014 3:59 pm

Hi guys,

I have setup a hotspot service using the Mikrotik Router as a service controler and an external access point. the user experience i was expecting is:
1) the user associate with tu SSID broadcasted by the AP
2) the user open a browser and tries to get to internet by entering a URL
3) the user is redirected to the login page hosted in Mikrotik
4) the user enters his login/pwd and is authenticated against a radius server

the issue i have is:
in step 2, if users enter an http url then everything works fine. However, in case they enter an https URL then they get a browser error saying: "the connection was reset, the connection to the server was reset while the page was loading......".

as far as i know, in case of SSL issue we get a warning from the browser saying "this site is not trusted.......if you want to continue click OK" so i was wondering if installing an SSL certificate will solve the issue.

Did someone have an idea about this issue?

Thanks
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12001
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: https redirect issue

Mon Jul 07, 2014 7:29 pm

Hi guys,

I have setup a hotspot service using the Mikrotik Router as a service controler and an external access point. the user experience i was expecting is:
1) the user associate with tu SSID broadcasted by the AP
2) the user open a browser and tries to get to internet by entering a URL
3) the user is redirected to the login page hosted in Mikrotik
4) the user enters his login/pwd and is authenticated against a radius server

the issue i have is:
in step 2, if users enter an http url then everything works fine. However, in case they enter an https URL then they get a browser error saying: "the connection was reset, the connection to the server was reset while the page was loading......".

as far as i know, in case of SSL issue we get a warning from the browser saying "this site is not trusted.......if you want to continue click OK" so i was wondering if installing an SSL certificate will solve the issue.

Did someone have an idea about this issue?

Thanks
1) assign one dns name to your hotspot, like hs.myservice.net

2) Buy one certificate here:
http://it.godaddy.com/ssl/ssl-certificates.aspx

3) set the hotspot to use your certificate
 
othmane
just joined
Topic Author
Posts: 8
Joined: Mon Apr 21, 2014 8:35 pm

Re: https redirect issue

Tue Jul 08, 2014 3:27 pm

Thank you Rextended for your answer,

can i use a self signed certificate for testing before buying a real one?
 
User avatar
c0d3rSh3ll
Long time Member
Long time Member
Posts: 557
Joined: Mon Jul 25, 2011 9:42 pm
Location: [admin@Chile] >

Re: https redirect issue

Tue Jul 08, 2014 5:59 pm

Thank you Rextended for your answer,

can i use a self signed certificate for testing before buying a real one?
Yes. You can generate in linux and upload to routerOS.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12001
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: https redirect issue

Tue Jul 08, 2014 6:06 pm

But everytime the device than connect to hotspot complain about unsigned - untrusted certificates, displayng warning messages, because your own cert, are not autorized by root certificates...
 
User avatar
c0d3rSh3ll
Long time Member
Long time Member
Posts: 557
Joined: Mon Jul 25, 2011 9:42 pm
Location: [admin@Chile] >

Re: https redirect issue

Tue Jul 08, 2014 6:51 pm

But everytime the device than connect to hotspot complain about unsigned - untrusted certificates, displayng warning messages, because your own cert, are not autorized by root certificates...
as he say:
can i use a self signed certificate for testing before buying a real one?
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12001
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: https redirect issue

Tue Jul 08, 2014 7:07 pm

But everytime the device than connect to hotspot complain about unsigned - untrusted certificates, displayng warning messages, because your own cert, are not autorized by root certificates...
as he say:
can i use a self signed certificate for testing before buying a real one?
I complete your reply because you omit that...
as far as i know, in case of SSL issue we get a warning from the browser saying "this site is not trusted.......if you want to continue click OK" so i was wondering if installing an SSL certificate will solve the issue.
If user use it's own self made cert, the issue he want solve is not solved....
 
sun
just joined
Posts: 2
Joined: Tue Aug 12, 2014 3:44 pm

Re: https redirect issue

Wed Aug 13, 2014 10:38 am

I'm facing same issue, I bought the Godaddy SSL Cert still get the warning page, which SSL Cert can support Mikrotik Hotspot to avoid the warning page?
 
User avatar
awacenter
Member Candidate
Member Candidate
Posts: 201
Joined: Thu Dec 09, 2004 12:58 pm
Location: Castellón
Contact:

Re: https redirect issue

Wed Aug 13, 2014 11:25 am

This is a money issue.

For my experience in MikroTik hotspot service, not all SSL certificates works fine. it depends of the Certificate Authoroty. There ara Level 1 to Level 3 or more.
CA Level 1 (wellknown companies such as verysign, GeoTrust...) certificates are in almost all user devices. There is CA certificate and your own signed certificate.

In a CA level 3, you have to upload to mikrotik the CA Level and CA level 2 certificate and you own signed certificate. This process are a little mess for the user devices.

CA level 1 is expensive and CA level 3 is cheaper.

Briefly, this is the reason: how well-known your Ca is.



If you like, karma+
 
salvatron
just joined
Posts: 7
Joined: Mon Aug 11, 2014 1:32 pm

Re: https redirect issue

Thu Aug 14, 2014 10:12 am

I don't understand.

In my case, I have the default login.html of Mikrotik.

If the customers navigate to any https web (google for example) , the Mikrotik not redirecto to login.html, but if the customer navigate to any http, the Mikrotik redirect to login page.

Why to put a certificate https? that domain? I have not a domain.

The solution is to buy a certificate?
 
salvatron
just joined
Posts: 7
Joined: Mon Aug 11, 2014 1:32 pm

Re: https redirect issue

Thu Nov 20, 2014 1:13 pm

I followed all the steps correctly

1) assign one dns name to your hotspot, like hs.myservice.net
2) Buy one certificate froma trusted certificator.
3) set the hotspot to use your certificate.

My login page is https now, and works fine, the certicicate is correct.

I type in the browser: http://www.google.com and redirect to login page fine:

Image

But if type https://www.google.com or type "blabla" in the address browser (IE, Firefox, Chrome), the browser show a error, with messages of hackers and warnings because the certification is not correct.

Image

Why put my certicate for google?
 
jaykay2342
Member
Member
Posts: 336
Joined: Tue Dec 04, 2012 2:49 pm
Location: /Vigor/LocalGroup/Milky Way/Earth/Europe/Germany

Re: https redirect issue

Wed Nov 26, 2014 2:56 pm

That error is usual and you can't avoid it! From the technical view a man in the middle attack is happening.

When you type https://google.com into you browser
1. It resolves google.com into an IP. Lets say it's 203.0.113.57.
2. The browser connect to TCP port 443 on 203.0.113.57.
3. The RouterOS system redirect this connection to its Hotspot system.
4. Browser and Hotspot are doing the SSL handshake. This includes that the hostspot is sending its certificate.
5. The browser sill "thinks" it connects to google.com. But as the browser has received a certificate which is for your hotspot and NOT for google.com it shows a warning.

Everything is working as is should.
 
rusellbernand
just joined
Posts: 7
Joined: Mon Dec 22, 2014 1:54 pm

Re: https redirect issue

Tue Dec 30, 2014 6:49 am

OK! you mentioned that you are entering the url but redirected to the login page i don't know whether you have entered many url to identify the exact problem. Also when entering url it shows 'the connection was reset' so You may do DNS look up to know the consumption of packet data after you find the same error then check with your internet service provider through the website http://www.whoisxy.com/ where i checked previously.

Who is online

Users browsing this forum: Bing [Bot], Google [Bot] and 46 guests