TLS Inspection
TLS Inspection is the controlled decryption of TLS-encrypted connections by a security component so that their content can be checked for malicious code, attacks or unauthorized data outflows. The traffic is then re-encrypted and forwarded to its destination. The terms SSL inspection and break and inspect are also in use.
Technically, the inspecting component – such as a firewall, a proxy or a cloud-based Secure Web Gateway (SWG) – acts as an intermediary: toward the endpoint, it identifies itself with certificates from a company-owned certificate authority that is stored as trusted on the managed devices. Since the majority of web traffic is encrypted today, threats would remain invisible to many network controls without TLS inspection. Data Loss Prevention (DLP) also depends on insight into encrypted content.
Limits are set by data protection and technology: for sensitive categories such as online banking or health services, exceptions are usually defined, and in Germany data protection and labor law requirements must also be observed. Applications with certificate pinning cannot be inspected, and decryption requires considerable computing power. Cloud-based implementations in a SASE platform shift this load to the provider.