The TOR client creates its own self-signed SSL certificate using a random common name (domain name) that changes after approximately every 30 minutes. After going around and around with this scenario without success, I decided to try and block access to the TOR exit nodes from our network.

