Burp Suite User Forum

Create new post

Getting a Certificate not accepted message from call to GraphQL in Burp Suite Enterprise.

Glenn | Last updated: May 04, 2021 02:41PM UTC

This is in reference to the problem reported on https://forum.portswigger.net/thread/i-am-having-a-problem-getting-a-graphql-call-to-be-processed-by-our-burp-suite-enterprise-a953216c. I am trying to get a response to my question about what should the parameters be set to on the call to RemoteCertifcateValicationCallback specially the certificate and the chain parameters. If they can't be set, then exactly what should I be doing to get the certificate on my Burp Suite Enterprise server to be accepted by the calling C# program? Thanks.

Uthman, PortSwigger Agent | Last updated: May 05, 2021 10:51AM UTC

Hi Glenn, Did you take a look at the latest reply on the other forum post? Can you look at the documentation below for an example of how to implement the RemoteCertifcateValicationCallback? Can you also share an updated PoC? - https://docs.microsoft.com/en-us/dotnet/api/system.net.security.remotecertificatevalidationcallback?view=net-5.0

Glenn | Last updated: May 05, 2021 06:38PM UTC

First my POC is gjones@mathematica-mpr.com. Thanks for your responses, we will be look at them to decide how we want to handle this.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.