Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Soner Tari

@sonertari@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Open-Source Cybersecurity Developer & Maintainer (since 2006), creating and evolving network defense tools like SSLproxy and UTMFW (formerly ComixWall)

4 Followers
5 Following
4 Posts
Joined May 27, 2025
ComixWall:
https://sites.google.com/site/comixwall
GitHub:
https://github.com/sonertari
GitHub Sponsors:
https://github.com/sponsors/sonertari
Buy me a coffee:
https://buymeacoffee.com/sonertari
thanks.dev:
https://thanks.dev/u/gh/sonertari
GitHub.io:
https://sonertari.github.io
Open post
Soner Tari @sonertari@infosec.exchange
· 7mo ago

Is HTTP/2 the "Final Boss" for open-source firewalls? 🛡️

For years, we’ve been forced to "downgrade" traffic just to inspect it. As a FOSS developer, I spent months trying to bridge the gap between HTTP/2 and legacy inspection tools in SSLproxy.

The result? A "Concurrency Density Spike" that can overwhelm even the best C-based proxies. 📈

In my latest article, I break down why we need to stop fighting the "Binary Frame" war and start focusing on the ICAP Path. It’s not just a fix for H2—it’s our only real ticket to supporting HTTP/3 (QUIC) and finally unblocking UDP port 443 without losing visibility.

#OpenSource #CyberSecurity #InfoSec #NetworkSecurity #HTTP2 #HTTP3 #SSLproxy #Suricata #Firewall #ICAP #SystemArchitecture

https://www.linkedin.com/pulse/i-tried-add-http2-sslproxy-here-why-stopped-we-need-icap-soner-tari-7x7mf

linkedin.com

I Tried to Add HTTP/2 to SSLproxy. Here is Why I Stopped. (We Need ICAP.)

Discover why Divert Mode creates a "density spike" in SSLproxy and why the ICAP path is the future for H2/H3 support in open-source firewalls like Suricata.

2
0
3
0
Open post
Soner Tari @sonertari@infosec.exchange
· 16mo ago

My FOSS SSLproxy Needs HTTP/2 Support for Next-Gen Network Security (The "Invisible Threat" is Growing)

I'm the long-time maintainer of SSLproxy (and the co-maintainer of SSLsplit), a unique open-source transparent SSL/TLS proxy. Its core strength lies in its ability to decrypt and divert network traffic to other security tools (like E2guardian, Snort IPS, POP3 proxy, SMTP proxy, Virus and Spam scanners as in my UTMFW firewall) for deep SSL inspection. It's truly the only FOSS tool offering this transparent, real-time diversion capability to enable UTM services on encrypted streams. (For context: popular tools like mitmproxy, while powerful, expect you to write/use extensions for inspection rather than diverting traffic for existing services.)

The Problem: HTTP/2 is Hiding Threats in Plain Sight

In 2025, nearly a third of all websites have adopted HTTP/2. Here's the critical challenge for open-source cybersecurity: Current FOSS security tools, including SSLproxy and many downstream listening programs (like E2guardian, Squid, Snort), often cannot fully understand or process this HTTP/2 traffic in real-time. This is a significant gap, as commercial closed-source firewalls and libraries do offer real-time HTTP/2 SSL inspection capabilities. (For context: there are open/closed-source solutions for offline analysis.)

Currently, SSLproxy either prevents HTTP/2 upgrade or allows you to bypass HTTP/2 traffic using its powerful filtering features. However, neither offers the deep, real-time inspection needed for comprehensive security.

This creates a dangerous "translation gap" in the open-source ecosystem, where a growing portion of encrypted internet traffic is effectively invisible to real-time deep inspection, forcing reliance on proprietary solutions for full visibility.

Why This Matters for You:

  • Deep Inspection is Blind: Without real-time HTTP/2 support, the vast majority of modern encrypted traffic bypasses essential content filtering, intrusion detection, and virus scanning that FOSS tools could otherwise provide.
  • Essential for UTM: Projects like my UTMFW heavily rely on SSLproxy to feed decrypted traffic into their core services. Lacking HTTP/2 support in SSLproxy (and integrated UTM services) means a critical blind spot in next-gen firewall capabilities.
  • Security Professionals Need It: If you're a cybersecurity professional relying on FOSS tools to inspect TCP, SSL/TLS, and HTTPS traffic for analysis, this directly impacts your ability to gain full visibility into modern network communications.

The Solution & The Challenge Ahead:

SSLproxy must evolve to natively speak HTTP/2 and transparently translate it back to HTTP/1 for seamless integration with existing downstream security tools. This is a substantial engineering effort, requiring the integration of complex libraries like nghttp2 and nghttpx, and a dedicated focus.

How You Can Help Fuel This Critical Work:

My FOSS projects are fueled by a deep commitment to open-source security, but developing and maintaining these complex, vital features demands significant time and resources. If you or your organization benefit from open-source network security tools like SSLproxy, your support is invaluable.

Sponsorship enables me to dedicate full-time effort to delivering crucial advancements like comprehensive HTTP/2 support, improved TLS compatibility, Windows support, and much more.

You can learn more about SSLproxy, UTMFW, and my other projects, including the full roadmap, here:

➡️ My New Website: https://sonertari.github.io

➡️ GitHub Project Boards (Full Roadmap): https://github.com/sonertari?tab=projects

#FOSS #Cybersecurity #NetworkSecurity #OpenSource #InfoSec #SSLproxy #UTMFW #HTTP2 #Firewall #IPS #Sponsorship #ComixWall

nghttp2.org

Nghttp2: HTTP/2 C Library - nghttp2.org

Nghttp2: HTTP/2 C Library Feb 16th, 2015 11:16 pm nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C. The …

1
0
0
0
Open post
Soner Tari @sonertari@infosec.exchange
· 10mo ago

UTMFW/PFFW/PFRE 7.8 released: https://github.com/sonertari/UTMFW/releases/tag/v7.8

GitHub

Release UTMFW 7.8 · sonertari/UTMFW

Highlights of this release are: SSLproxy 0.9.9 Variety of fixes and improvements

0
0
0
0
Open post
Soner Tari @sonertari@infosec.exchange
· 10mo ago

SSLproxy 0.9.9 released: https://github.com/sonertari/SSLproxy/releases/tag/v0.9.9

GitHub

Release SSLproxy 0.9.9 · sonertari/SSLproxy

Fix fd leak, do not setup dst again in autossl, issue #88 reported by @victorjulien Fix memory leak in config load, reported by valgrind Disable r/w cbs and clear all cbs before all bufferevent_fre...

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:45:57 UTC