The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burpsuite CA not working for sub-domain?

steve | Last updated: Jul 17, 2016 04:25AM UTC

Hi I encountered a scenario. I am on Burpsuite Pro. I am testing an SSL enabled site https://myexamplesite.com/ and I was able to use the Burpsuite CA to act as MITM to load the content into Burpsuite successfully. However, the site has a subdomain http://sub1.myexamplesite.com/ and I loaded the Burpsuite CA into this subdomain but I was hit with a "Received fatal alert: handshake_failure" message in my Burpsuite alerts. I have already ensured the following: - updated the latest JCE - disabled java SNI extension by doing the following -Djsse.enableSNIExtension=false Could any experts please give some advise? Why doesn't the CA cert works for subdomain? Is it because there is Public Key Certificate Pinning enabled somehow?

PortSwigger Agent | Last updated: Jul 18, 2016 12:38PM UTC