The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp signed SSL certificates throw warning in Chrome

Spencer | Last updated: Jun 10, 2015 07:28PM UTC

When burp generates CA-signed per-host certificates, Google Chrome marks these sites as having "Weak Security configuration (SHA-1 signatures), so your connections may not be private. Screenshot: http://i.imgur.com/B5XcMF9.png It looks like Chrome is actively trying to sunset SHA-1 (https://blog.filippo.io/the-unofficial-chrome-sha1-faq/) So, I'm guessing this message can be removed if Burp signed the per host certificates with sha-256?

PortSwigger Agent | Last updated: Jun 11, 2015 08:03AM UTC