The same online-config repo's Flink ETL "completion" topology (deployed at both DC and NC tiers) processes a dedicated "PXY-EXCH-INTERMEDIA-CERT" event stream alongside SYS-PACKET-CAPTURE-EVENT and ETL-SESSION-RECORD-COMPLETED — production-pipeline evidence that proxy/TLS certificate-exchange (i.e. TLS-interception) events are logged and processed at scale across live field deployments, not just tested in isolation.
flink/DC/topology/completion/config/PXY-EXCH-INTERMEDIA-CERT
Defense implications
- Confirms a production event stream specifically for proxy/TLS certificate-exchange events exists in the analytics pipeline at fielded sites — treat active MITM/certificate-substitution as an operationally logged and monitored capability at scale, not a lab-only feature; client-side certificate pinning/verification remains necessary rather than trusting network-path TLS alone.
capabilitymitm-cert-implant