Burp Suite User Forum

Create new post

BurpSuite Professional - Error No Supported CertificateVerify signature algorithm for RSA key

sammysrh | Last updated: Jan 11, 2022 08:57PM UTC

Hello I am having an issue when attempting to use my HardToken (CAC) certificates in tandem with burpsuite. I provide the certificates via Project Options > TLS > Client TLS Certificates > Override user options and inputting them in there. Once I do this and attempt to access the HardToken Authenticated website it states the following error "No supported CertificateVerify signature algorithm for RSA Key". Outside of burpsuite, access works just fine. How do I get this to work with Burpsuite?

Uthman, PortSwigger Agent | Last updated: Jan 12, 2022 10:48AM UTC

Hi Kirby,

Can you please replicate the issue and email support@portswigger.net with the information below?

  • A screen recording of the issue replicated
  • Diagnostics (Help > Diagnostics)
  • Enable Log exceptions to a local directory under User options > Misc > Performance Feedback. Then replicate the issue and share the exceptions log file if one is generated `
  • Information on how the certificates were created (i.e. what signature algorithms, etc...)

Adam | Last updated: Feb 07, 2023 07:30PM UTC

What was the solution to this? I am running into the exact same error "No supported CertificateVerify signature algorithm for RSA key" when I am proxying through Firefox.

Michelle, PortSwigger Agent | Last updated: Feb 08, 2023 01:35PM UTC

Hi It would be good to check a few more details about the setup and the certificates being used. If you'd prefer to share these directly with us rather than posting the details on the public forum, please feel free to email support@portswigger.net and reference this thread. - Do you see this error both when proxying Firefox via Burp and when using Burp's embedded browser? - Do you see any errors when sending the requests to the same site using Repeater? - Have you imported the client certificate under Settings -> Network -> TLS -> Client TLS certificates? - Is the client certificate signed by a root CA or an intermediate CA?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.