I want to ask you if you think that doing SSL Inspection in proxy mode (Resign) could be a problem.
The scenario is the following:
1 --> 2 --> 3
- Client web browsing
- IPS device with SSL inspection (client trusts the certificate of the IPS because the IPS became a subordinate CA of the CA)
- After that the traffic goes to the cloud where it is again resigned by the cloud proxy.
What do you think? Is it possible to realize it? The cloud proxy should be a subordinate CA of the CA?