So I'm sure you guys may have heard the news about HTTPS interception weaknesses concerning certificate validation. If you haven't heard check out the following article on DarkReading,
US-CERT Warns That HTTPS Inspection Tools Weaken TLS.
Personally, I am surprised that numerous HTTPS Interception products do not properly validate certificates. I am currently in discussions with our Web Content Filtering product provider on their product's lack of certificate validation. It seems like they have been fully aware of the issue for some time now and with this finding, are now just addressing it.
Thoughts?