Hi,
I believe I have discovered a problem with the way users are captured by the MikroTik Hotspot. If the Hotspot is implemented using an SSL Certificate and only allows Hotspot Portal logins via HTTPS, any user whose Home Page or manually selected initial page is SSL protected, can receive a Certificate error in their Browser.
This seems to happen because the MikroTik Hotspot captures the session and simply returns it's own reply. This is interpreted by some Browsers as an SSL "man in the middle" attack.
Ideally when capturing the user session instead of simply replying, the Hotspot should issue an HTTP redirect to the https://hotspot.domain/login URL.
This problem occurs on all RouterOS versions at or above v4.10, don't know about other versions. Definitely affects FireFox, Internet Explorer seems to be more random, some users of IE8 are affected and some aren't, so far I have been unable to identify why.
I believe our Hotspot is correctly configured, we're using a GoDaddy SSL Cert and the intermediate Root Certs are installed on the Hotspot.
Anyone else experienced these problems and/or found a solution?
Regards
Chris Macneill