There's no TLS inspection for youtube, original certificate appears. TLS connections over youtube.com domain is safe for now.
$ openssl s_client -showcerts -servername www.youtube.com -connect 85.117.236.90:443
CONNECTED(00000003)
depth=0 C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
verify error:num=18:self signed certificate
verify return:1
depth=0 C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
verify return:1
---
Certificate chain
0 s:C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
i:C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
-----BEGIN CERTIFICATE-----
@@@
-----END CERTIFICATE-----
---
Server certificate
subject=C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
issuer=C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
---
There's TLS inspection for other domains, MEB's fatihca certificate appears.
$ openssl s_client -showcerts -servername www.google.com -connect 85.117.236.90:443
CONNECTED(00000003)
depth=1 C = TR, L = ANKARA, O = MEB, OU = BIDB, CN = IZM-UTM-FGT-07, emailAddress = [email protected]
verify error:num=20:unable to get local issuer certificate
verify return:1
depth=0 C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
verify return:1
---
Certificate chain
0 s:C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
i:C = TR, L = ANKARA, O = MEB, OU = BIDB, CN = IZM-UTM-FGT-07, emailAddress = [email protected]
-----BEGIN CERTIFICATE-----
@@@
-----END CERTIFICATE-----
1 s:C = TR, L = ANKARA, O = MEB, OU = BIDB, CN = IZM-UTM-FGT-07, emailAddress = [email protected]
i:DC = tr, DC = gov, DC = mebca, CN = fatihca
-----BEGIN CERTIFICATE-----
@@@
-----END CERTIFICATE-----
---
Server certificate
subject=C = TR, ST = Some-State, O = Internet Widgits Pty Ltd
issuer=C = TR, L = ANKARA, O = MEB, OU = BIDB, CN = IZM-UTM-FGT-07, emailAddress = [email protected]
---