The community will be in read-only from Tuesday 11:59pm (PST) to Wednesday 7:30am (PST)
The community will be in read-only from Tuesday 11:59pm (PST) to Wednesday 7:30am (PST)
WebInspect
cancel
Showing results for 
Search instead for 
Did you mean: 

"This connection is untrusted" - Certificate Problem

k1DBLITZ
Regular Collector

"This connection is untrusted" - Certificate Problem

Using Webinspect 9.20

 

Attempting to record a login marco for an internal site using an SSL certificate signed by our internal CA.

 

Details state:

 

"domainIamscanning.com uses an invalid security certificate.

The certificate is not trusted because the issuer certificate is unknown."

 

If I click "add an exception" and check "permanently store this exceptioin" it doesn't stick. 

 

I have also installed our Root and Intermediate certificates into the respective Windows Certificate Store and restarted WebInspect. It still refuses to trust the cert.

 

Any ideas?

3 REPLIES
k1DBLITZ
Regular Collector

Re: "This connection is untrusted" - Certificate Problem

Update: I've also tried adding the root and intermediate certificates by launched the browser in the HP hive. It doesn't seem to carry over while in WebInspect...which seems odd. 

Highlighted
k1DBLITZ
Regular Collector

Re: "This connection is untrusted" - Certificate Problem

I am also experiencing this same problem in Webinspect 9.30

HansEnders
Honored Contributor

Re: "This connection is untrusted" - Certificate Problem

WebInspect does not use the IE browser, but its own internal-yet-equivalent one, and this includes the acceptance of certificates.  In actual use, the scanner simply accepts all certs and moves on, as its aim is to scan and not be a safe browser.

 

The complication here may be in the Macro Recorder and the replay of your Macro.  I would record the macro, but then mark any certificate acceptance sessions as "Optional".  With this edit, those sessions can either be present or not during the actual replay of the Macro during the live scan, and it will not affect the replay.


-- Habeas Data
HPE Fortify Customers-Only Forums – https://protect724.hpe.com/community/fortify
//Add this to "OnDomLoad" event