SOURCINGBLOX DEMake an appointment
Menu
For security engineering, networking, data protection, and Zscaler administration

TLS inspection: Inspect encrypted traffic without blindly breaking applications.

TLS inspection creates visibility in encrypted data traffic. At the same time, it changes certificate chains and can collide with mTLS, certificate pinning, data protection requirements or sensitive applications. Good introduction therefore means: controlled testing, justifying exceptions and measuring impact.

Briefly explained

What does TLS inspection mean?

With TLS inspection, an encrypted connection is terminated, checked and re-established to the target at a controlled security component. To do this, clients must trust the certificate chain used and policies must decide which traffic is checked or excluded.

The Problem: More Visibility Meets Certificate and Application Dependencies

Without inspection, content and threats in HTTPS connections remain partially invisible to inline controls. However, blanket decryption can interfere with applications that use certificate pinning, mutual TLS authentication, or special privacy rules.

Unverified bypass lists are growing rapidly. Each exception reduces visibility and can no longer be assigned to anyone later on.

Typical scenario

After the inspection has been activated, a mobile specialist application will no longer work. The quick reaction would be a broad domain bypass. The better way is to check certificate errors, pinning, target hosts, user group, and data class, and limit an exception to the minimum required.

Four levels of failure analysis

Not every TLS glitch has the same cause.

Trust Chain

Check root and intermediate certificates, browser stores, operating systems, and managed devices.

Handshake

TLS version, cipher, SNI, mTLS, and server properties.

Application

Capture certificate pinning, native clients, updates, and external dependencies.

Policy

Check rule order, category, user, location, cloud app, and bypass reason.

What needs to be checked before making a decision?

  • Is the inspection certificate trustworthy on all affected devices?
  • Is it browser, app, or mTLS traffic?
  • What FQDNs and dependent targets are called?
  • Which policy and category actually apply?
  • Is an exception technically necessary and technically approved?
  • How is the exception checked and removed later?

Definition: A bypass is a conscious risk decision, not a general repair. Data protection, labor law and regulatory requirements must be evaluated on an organization-specific basis.

How SourcingBlox Inspects in a Controlled Way

We combine technical testing with policy and governance decisions.

01

Readiness Review

Capture certificate distribution, devices, apps, privacy classes, and current exceptions.

02

Pilot & Compatibility

Test representative users and applications, measure error patterns and cut exceptions minimally.

03

Policy Governance

Document the owner, justification, duration, review, and revocation of each exception.

Typical mistakes

  • Root certificates are not fully distributed.
  • Broad categories instead of concrete dependencies.
  • Confusing certificate pinning and mTLS.
  • Leave bypasses without owner and resubmission permanently.

Frequently Asked Questions

Why do some apps break during TLS inspection?

Often due to lack of certificate chain of trust, certificate pinning, mTLS, or unrecorded dependent hosts.

Should financial or health transactions always be exempted?

This is an organization- and law-dependent policy decision. It should not be derived from marketing texts across the board.

How small should a bypass be?

As specific as technically possible: limited to necessary goals, user, app or context and with a review date.

Concrete next step

Check a specific TLS glitch or bypass list.

We analyze the trust chain, application, policy and risk and develop a controlled next step.

View Inspection Review

Related Content

Sources and further information

Specific policy options and exceptions must be checked against the current tenant and product documentation before implementation.