The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Passing Smart Card through to OneID Website Accessed via Remote Desktop

Justin | Last updated: Sep 12, 2024 02:21AM UTC

Hello, We are using Burp Suite Professional on a remote server, and whenever we attempt to access a website behind OneID with the burp proxy enabled, it fails to read our PIV card. We set it up via the following: Within "Settings > Network > TLS", under "Client TLS certificates", we have wildcard destination hosts with "Certificate type: Hardware or smart card (PKCS#11)" and the library file being the ActivClient acpkcs211 library. We were able to input our PIN code, and select the authentication certificate from our PIV card. When we navigate to a website behind OneID with the proxy enabled, no luck, PIV Card Verification fails. (Turning off the proxy, PIV card verification succeeds). Any advice? We will be asking the OneID folks as well, I just wanted to check here in case this is a standard use case with a known solution. Thank you!

Michelle, PortSwigger Agent | Last updated: Sep 12, 2024 08:12AM UTC