What does TLS inspection mean?
With TLS inspection, an encrypted connection is terminated, checked and re-established to the target at a controlled security component. To do this, clients must trust the certificate chain used and policies must decide which traffic is checked or excluded.
The Problem: More Visibility Meets Certificate and Application Dependencies
Without inspection, content and threats in HTTPS connections remain partially invisible to inline controls. However, blanket decryption can interfere with applications that use certificate pinning, mutual TLS authentication, or special privacy rules.
Unverified bypass lists are growing rapidly. Each exception reduces visibility and can no longer be assigned to anyone later on.
After the inspection has been activated, a mobile specialist application will no longer work. The quick reaction would be a broad domain bypass. The better way is to check certificate errors, pinning, target hosts, user group, and data class, and limit an exception to the minimum required.
Four levels of failure analysis
Not every TLS glitch has the same cause.
Trust Chain
Check root and intermediate certificates, browser stores, operating systems, and managed devices.
Handshake
TLS version, cipher, SNI, mTLS, and server properties.
Application
Capture certificate pinning, native clients, updates, and external dependencies.
Policy
Check rule order, category, user, location, cloud app, and bypass reason.
What needs to be checked before making a decision?
- Is the inspection certificate trustworthy on all affected devices?
- Is it browser, app, or mTLS traffic?
- What FQDNs and dependent targets are called?
- Which policy and category actually apply?
- Is an exception technically necessary and technically approved?
- How is the exception checked and removed later?
Definition: A bypass is a conscious risk decision, not a general repair. Data protection, labor law and regulatory requirements must be evaluated on an organization-specific basis.
How SourcingBlox Inspects in a Controlled Way
We combine technical testing with policy and governance decisions.
Readiness Review
Capture certificate distribution, devices, apps, privacy classes, and current exceptions.
Pilot & Compatibility
Test representative users and applications, measure error patterns and cut exceptions minimally.
Policy Governance
Document the owner, justification, duration, review, and revocation of each exception.
Typical mistakes
- Root certificates are not fully distributed.
- Broad categories instead of concrete dependencies.
- Confusing certificate pinning and mTLS.
- Leave bypasses without owner and resubmission permanently.
Frequently Asked Questions
Why do some apps break during TLS inspection?
Often due to lack of certificate chain of trust, certificate pinning, mTLS, or unrecorded dependent hosts.
Should financial or health transactions always be exempted?
This is an organization- and law-dependent policy decision. It should not be derived from marketing texts across the board.
How small should a bypass be?
As specific as technically possible: limited to necessary goals, user, app or context and with a review date.
Check a specific TLS glitch or bypass list.
We analyze the trust chain, application, policy and risk and develop a controlled next step.
Related Content
Sources and further information
Specific policy options and exceptions must be checked against the current tenant and product documentation before implementation.
