PAC-K006 · https-proxy-keyword-without-fallback

HTTPS proxy keyword without a PROXY fallback

medium · Compatibility across engines

"HTTPS host:port" tells the browser to open TLS to the proxy itself. Chromium and Firefox support it; WinHTTP-based clients do not, and most on-premises proxies have no TLS listener. Without a PROXY fallback those clients end up without a proxy.

Why it matters

The HTTPS keyword is not “proxy for https traffic”; it means the client-to-proxy hop is TLS. It is correct for cloud gateways that terminate TLS on their listener and wrong for the typical enterprise forward proxy that accepts plain HTTP CONNECT. Engines that do not know the keyword drop the entry (PAC-E011). Two failure shapes follow: a WinHTTP client sees an empty list and goes DIRECT; a browser opens TLS to a proxy that speaks plain HTTP and the connection fails. If HTTPS is intended, keep a PROXY fallback in the same list for clients that cannot use it, and verify the proxy actually offers TLS.

How to fix

Use "PROXY host:port" for plain-HTTP proxies; for a TLS-terminating gateway write "HTTPS gw:443; PROXY gw:8080" so that other engines still get a proxy.

Examples

Bad

function FindProxyForURL(url, host) {
  return "HTTPS gateway.corp.example:443";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  return "HTTPS gateway.corp.example:443; PROXY gateway.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromium"HTTPS host:port" is an accepted PAC return keyword (TLS to the proxy; HTTP/2 to the proxy is possible, QUIC is not selectable from PAC).doc, verified 2026-10-04 · ref
firefoxHTTPS keyword supported in current versions.expert, unverified
winhttpReported not to support the HTTPS keyword.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References