Burp Suite User Forum

Create new post

Configure Burp to Allow Revoked Certificates ?

m | Last updated: Dec 14, 2020 09:28AM UTC

I need to allow burp ignore revoked cert problems. How can i do that ?

Uthman, PortSwigger Agent | Last updated: Dec 14, 2020 10:34AM UTC

Can you clarify what you are trying to do?

m | Last updated: Dec 15, 2020 03:52PM UTC

I am trying to scan a web application (with burp pro) which uses a revoked SSL on it. And burp notification says "no response from remote server". But when i disable oscp responder (which is used to check if the certificate is revoked) on my mozilla browser i can actually access to web content over https. I need Burp to ignore this specific certification error. As i googled i found that i can use the flag -Dcom.sun.net.ssl.checkRevocation=false on JVM but unfortunaltely i use exe version of Burp. I configured "Disable Java SNI" (i restarted as suggested) and accepted all the enryption options on Burp (although i knew it is nothing to do with) still no success.

Uthman, PortSwigger Agent | Last updated: Dec 16, 2020 10:28AM UTC

Thanks for the feedback. If you navigate to the installation directory of the .exe, there should be a VMOPTIONS file. Can you try adding the JVM parameter to that and relaunch Burp?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.