Burp Suite User Forum

Create new post

Global settings for SSL pass-through

Zhaolin | Last updated: Feb 28, 2018 02:48PM UTC

It would be great if we can configure SSL pass-through globally. For example, Google Analysis and Google Translation are typically out of scope of ordinary user. Current per-project setting is expected to override global settings, including adding rules or disabling rules. That is, project setting should be able to specify that an SSL/TLS connection is passed through only if the hostname does *not* match certain regular expression.

PortSwigger Agent | Last updated: Feb 28, 2018 04:26PM UTC

Hi Zhaolin, Thanks for your suggestion. We recommend that SSL pass-through only be used where it is needed to workaround connection problems. For domains you're not interested in, you can not include them in your scope.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.