Recording stops due to HSTS

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
9 messages Options
Reply | Threaded
Open this post in threaded view
|

Recording stops due to HSTS

Amarendra Darisa
Hi,

I am trying to record a transaction but hit a page which says is using HSTS. It doesn’t allow me add an exception. As i am on mac, i double checked the jMeter cert permissions again which seem to be fine. Please suggest how to get this issue resolved. I am doing this on mac with chrome browser.



- Amar



Reply | Threaded
Open this post in threaded view
|

RE: Recording stops due to HSTS

rhintintin
This post has NOT been accepted by the mailing list yet.

Do you have the cert generated by jmeter in recording mode added into your certificate authorities?

 

I don’t use Chrome, but in firefox I import the cert created in Bin when recording is started, into certificate authorities.

 

The cert expires after a set number of days (3 I think), however this can be changed in preferences.

 

From: Amarendra Darisa [via JMeter] [mailto:ml+[hidden email]]
Sent: 12 May 2017 10:22
To: Chris Grey <[hidden email]>
Subject: Recording stops due to HSTS

 

Hi,

 

I am trying to record a transaction but hit a page which says is using HSTS. It doesn’t allow me add an exception. As i am on mac, i double checked the jMeter cert permissions again which seem to be fine. Please suggest how to get this issue resolved. I am doing this on mac with chrome browser.

 

Image removed by sender.


- Amar

 

 

 

 


If you reply to this email, your message will be added to the discussion below:

http://www.jmeter-archive.org/Recording-stops-due-to-HSTS-tp5725606.html

To unsubscribe from JMeter - User, click here.
NAML

-----------------------------------------------

Consider the environment: Please don't print this e-mail unless you really need to.

Confidentiality: This email and its attachments are intended for the above named only and may be confidential. If they have come to you in error you must take no action based on them, nor must you copy or show them to anyone; please reply to this email and highlight the error.

Viruses: Although we have taken steps to ensure that this email and attachments are free from any virus, we advise that in keeping with good computing practice the recipient should ensure that they are actually virus-free.

Brokerage Services provided by TD Direct Investing (Europe) Limited (a subsidiary of The Toronto-Dominion Bank). Incorporated in England and Wales under registration number 2101863. Registered office: Exchange Court, Duncombe Street, Leeds, LS1 4AX, United Kingdom. Authorised and regulated by the Financial Conduct Authority, 25 The North Colonnade, Canary Wharf, London, E14 5HS, United Kingdom (Financial Services Register Firm Reference Number 141282), member of the London Stock Exchange and the ICAP Securities and Derivatives Exchange. VAT Registration No. 397103051. www.tddirectinvesting.co.uk

Banking Services provided by TD Bank N.V. Incorporated in the Netherlands and registered as a branch in England and Wales under branch registration number BR006780. Authorised by the Dutch Central Bank (De Nederlandsche Bank - DNB Institution Number 481) and subject to limited regulation by the Financial Conduct Authority and Prudential Regulation Authority (Financial Services Register Firm Reference Number 216791). Details about the extent of our regulation by the Financial Conduct Authority and Prudential Regulation Authority are available from us on request.

------------------------------------------------

Reply | Threaded
Open this post in threaded view
|

Re: Recording stops due to HSTS

glinius@live.com
This post has NOT been accepted by the mailing list yet.
In reply to this post by Amarendra Darisa
Try re-importing JMeter self-signed certificate into your browser, i.e.

 1. Delete the previously imported certificate
 2. Delete ApacheJMeterTemporaryRootCA.crt file under JMeter's "bin" folder
 3. Start HTTP(S) Test Script Recorder
 4. Import newly generated ApacheJMeterTemporaryRootCA.crt file into Chrome browser.

See HTTPS recording and certificates chapter of the HTTP(S) Test Script Recorder JMeter User Manual entry for more details.

JMeter self-signed certificate has a limited life time (7 days as per JMeter 3.2) so it might be the case it has expired.

Also you can consider an alternative way of recording a JMeter test - JMeter Chrome Extension, in this case you won't need to worry about proxies, SSL certificates, etc. so you will be able to just follow your test scenario steps in the browser and the extension will record them. Once done you should be able to export it as .jmx test script.  
Reply | Threaded
Open this post in threaded view
|

Re: Recording stops due to HSTS

Felix Schumacher
In reply to this post by Amarendra Darisa
Am 12.05.2017 um 11:21 schrieb Amarendra Darisa:
Hi,

I am trying to record a transaction but hit a page which says is using HSTS. It doesn’t allow me add an exception. As i am on mac, i double checked the jMeter cert permissions again which seem to be fine. Please suggest how to get this issue resolved. I am doing this on mac with chrome browser.
Have you imported the generated JMeter testing certificate into your browser? I had no problem accessing the site through JMeter's proxy (when I imported the cert  ApacheJMeterTemporaryRootCA.crt from the bin/ directory)

Regards,
 Felix




- Amar




Reply | Threaded
Open this post in threaded view
|

Re: Recording stops due to HSTS

Charles Lin (charlin)

Hi all,

 

I have the same problem.

 

I’ve done this HTTP Recorder over 1.5 year ago and no problem

 

But now I do the same, and have imported (installed) the proxy cert generated by jmeter into Firefox, but I am getting the same warning about site using HSTS and cannot add exception

 

From: Felix Schumacher <[hidden email]>
Reply-To: "[hidden email]" <[hidden email]>
Date: Monday, May 22, 2017 at 10:03 AM
To: "[hidden email]" <[hidden email]>
Subject: Re: Recording stops due to HSTS

 

Am 12.05.2017 um 11:21 schrieb Amarendra Darisa:

Hi,

 

I am trying to record a transaction but hit a page which says is using HSTS. It doesn’t allow me add an exception. As i am on mac, i double checked the jMeter cert permissions again which seem to be fine. Please suggest how to get this issue resolved. I am doing this on mac with chrome browser.

Have you imported the generated JMeter testing certificate into your browser? I had no problem accessing the site through JMeter's proxy (when I imported the cert  ApacheJMeterTemporaryRootCA.crt from the bin/ directory)

Regards,
 Felix


 


- Amar

 

 

 

 

Reply | Threaded
Open this post in threaded view
|

Re: Recording stops due to HSTS

Felix Schumacher


Am 22. Mai 2017 20:52:12 MESZ schrieb "Charles Lin (charlin)" <[hidden email]>:
>Hi all,
>
>I have the same problem.
>
>I’ve done this HTTP Recorder over 1.5 year ago and no problem
>
>But now I do the same, and have imported (installed) the proxy cert
>generated by jmeter into Firefox, but I am getting the same warning
>about site using HSTS and cannot add exception

The security measures in modern browsers get tighter each year. It might be possible, that the browser you used last time was configured less secure.

Which site have you tried? Can you look at the headers it sends? It might send some public key pinning header.

More information might be helpful.

Regards,
 Felix

>
>From: Felix Schumacher <[hidden email]>
>Reply-To: "[hidden email]" <[hidden email]>
>Date: Monday, May 22, 2017 at 10:03 AM
>To: "[hidden email]" <[hidden email]>
>Subject: Re: Recording stops due to HSTS
>
>Am 12.05.2017 um 11:21 schrieb Amarendra Darisa:
>Hi,
>
>I am trying to record a transaction but hit a page which says is using
>HSTS. It doesn’t allow me add an exception. As i am on mac, i double
>checked the jMeter cert permissions again which seem to be fine. Please
>suggest how to get this issue resolved. I am doing this on mac with
>chrome browser.
>Have you imported the generated JMeter testing certificate into your
>browser? I had no problem accessing the site through JMeter's proxy
>(when I imported the cert  ApacheJMeterTemporaryRootCA.crt from the
>bin/ directory)
>
>Regards,
> Felix
>
>
>
>[cid:image001.png@01D2D2F1.D87FC850]
>
>- Amar

---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]

pmd
Reply | Threaded
Open this post in threaded view
|

Re: Recording stops due to HSTS

pmd
Hello,
Did you try Felix proposal ? If so could you give some feedback?

did you add the JMeter Certificate to your browser (and remove old one)  :
http://jmeter.apache.org/usermanual/component_reference.html#HTTP(S)_Test_
Script_Recorder
See:
Installing the JMeter CA certificate for HTTPS recording



Thanks

On Tue, May 23, 2017 at 8:34 AM, Felix Schumacher <
[hidden email]> wrote:

>
>
> Am 22. Mai 2017 20:52:12 MESZ schrieb "Charles Lin (charlin)" <
> [hidden email]>:
> >Hi all,
> >
> >I have the same problem.
> >
> >I’ve done this HTTP Recorder over 1.5 year ago and no problem
> >
> >But now I do the same, and have imported (installed) the proxy cert
> >generated by jmeter into Firefox, but I am getting the same warning
> >about site using HSTS and cannot add exception
>
> The security measures in modern browsers get tighter each year. It might
> be possible, that the browser you used last time was configured less secure.
>
> Which site have you tried? Can you look at the headers it sends? It might
> send some public key pinning header.
>
> More information might be helpful.
>
> Regards,
>  Felix
> >
> >From: Felix Schumacher <[hidden email]>
> >Reply-To: "[hidden email]" <[hidden email]>
> >Date: Monday, May 22, 2017 at 10:03 AM
> >To: "[hidden email]" <[hidden email]>
> >Subject: Re: Recording stops due to HSTS
> >
> >Am 12.05.2017 um 11:21 schrieb Amarendra Darisa:
> >Hi,
> >
> >I am trying to record a transaction but hit a page which says is using
> >HSTS. It doesn’t allow me add an exception. As i am on mac, i double
> >checked the jMeter cert permissions again which seem to be fine. Please
> >suggest how to get this issue resolved. I am doing this on mac with
> >chrome browser.
> >Have you imported the generated JMeter testing certificate into your
> >browser? I had no problem accessing the site through JMeter's proxy
> >(when I imported the cert  ApacheJMeterTemporaryRootCA.crt from the
> >bin/ directory)
> >
> >Regards,
> > Felix
> >
> >
> >
> >[cid:image001.png@01D2D2F1.D87FC850]
> >
> >- Amar
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [hidden email]
> For additional commands, e-mail: [hidden email]
>
>


--
Cordialement.
Philippe Mouawad.
Reply | Threaded
Open this post in threaded view
|

Re: Recording stops due to HSTS

Charles Lin (charlin)
Yes, have removed old and installed new cert, but still does not work

On 5/25/17, 6:56 AM, "Philippe Mouawad" <[hidden email]> wrote:

    Hello,
    Did you try Felix proposal ? If so could you give some feedback?
   
    did you add the JMeter Certificate to your browser (and remove old one)  :
    http://jmeter.apache.org/usermanual/component_reference.html#HTTP(S)_Test_
    Script_Recorder
    See:
    Installing the JMeter CA certificate for HTTPS recording
   
   
   
    Thanks
   
    On Tue, May 23, 2017 at 8:34 AM, Felix Schumacher <
    [hidden email]> wrote:
   
    >
    >
    > Am 22. Mai 2017 20:52:12 MESZ schrieb "Charles Lin (charlin)" <
    > [hidden email]>:
    > >Hi all,
    > >
    > >I have the same problem.
    > >
    > >I’ve done this HTTP Recorder over 1.5 year ago and no problem
    > >
    > >But now I do the same, and have imported (installed) the proxy cert
    > >generated by jmeter into Firefox, but I am getting the same warning
    > >about site using HSTS and cannot add exception
    >
    > The security measures in modern browsers get tighter each year. It might
    > be possible, that the browser you used last time was configured less secure.
    >
    > Which site have you tried? Can you look at the headers it sends? It might
    > send some public key pinning header.
    >
    > More information might be helpful.
    >
    > Regards,
    >  Felix
    > >
    > >From: Felix Schumacher <[hidden email]>
    > >Reply-To: "[hidden email]" <[hidden email]>
    > >Date: Monday, May 22, 2017 at 10:03 AM
    > >To: "[hidden email]" <[hidden email]>
    > >Subject: Re: Recording stops due to HSTS
    > >
    > >Am 12.05.2017 um 11:21 schrieb Amarendra Darisa:
    > >Hi,
    > >
    > >I am trying to record a transaction but hit a page which says is using
    > >HSTS. It doesn’t allow me add an exception. As i am on mac, i double
    > >checked the jMeter cert permissions again which seem to be fine. Please
    > >suggest how to get this issue resolved. I am doing this on mac with
    > >chrome browser.
    > >Have you imported the generated JMeter testing certificate into your
    > >browser? I had no problem accessing the site through JMeter's proxy
    > >(when I imported the cert  ApacheJMeterTemporaryRootCA.crt from the
    > >bin/ directory)
    > >
    > >Regards,
    > > Felix
    > >
    > >
    > >
    > >[cid:image001.png@01D2D2F1.D87FC850]
    > >
    > >- Amar
    >
    > ---------------------------------------------------------------------
    > To unsubscribe, e-mail: [hidden email]
    > For additional commands, e-mail: [hidden email]
    >
    >
   
   
    --
    Cordialement.
    Philippe Mouawad.
   


---------------------------------------------------------------------
To unsubscribe, e-mail: [hidden email]
For additional commands, e-mail: [hidden email]
Reply | Threaded
Open this post in threaded view
|

Re: Recording stops due to HSTS

Lily Nguyen
I had the same issue with JMeter 3.2 , using Chrome.  I got it resolved by
invoking Chrome from command line with flag --ignore-certificate-errors
...This would get rid of the "Your connection is not private" error and i
was able to record normally after installing the certificate everywhere.

Good luck!
--Lily,

<http://www.avg.com/email-signature?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
Virus-free.
www.avg.com
<http://www.avg.com/email-signature?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
<#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>

On Mon, Jun 5, 2017 at 8:28 PM, Charles Lin (charlin) <[hidden email]>
wrote:

> Yes, have removed old and installed new cert, but still does not work
>
> On 5/25/17, 6:56 AM, "Philippe Mouawad" <[hidden email]>
> wrote:
>
>     Hello,
>     Did you try Felix proposal ? If so could you give some feedback?
>
>     did you add the JMeter Certificate to your browser (and remove old
> one)  :
>     http://jmeter.apache.org/usermanual/component_
> reference.html#HTTP(S)_Test_
>     Script_Recorder
>     See:
>     Installing the JMeter CA certificate for HTTPS recording
>
>
>
>     Thanks
>
>     On Tue, May 23, 2017 at 8:34 AM, Felix Schumacher <
>     [hidden email]> wrote:
>
>     >
>     >
>     > Am 22. Mai 2017 20:52:12 MESZ schrieb "Charles Lin (charlin)" <
>     > [hidden email]>:
>     > >Hi all,
>     > >
>     > >I have the same problem.
>     > >
>     > >I’ve done this HTTP Recorder over 1.5 year ago and no problem
>     > >
>     > >But now I do the same, and have imported (installed) the proxy cert
>     > >generated by jmeter into Firefox, but I am getting the same warning
>     > >about site using HSTS and cannot add exception
>     >
>     > The security measures in modern browsers get tighter each year. It
> might
>     > be possible, that the browser you used last time was configured less
> secure.
>     >
>     > Which site have you tried? Can you look at the headers it sends? It
> might
>     > send some public key pinning header.
>     >
>     > More information might be helpful.
>     >
>     > Regards,
>     >  Felix
>     > >
>     > >From: Felix Schumacher <[hidden email]>
>     > >Reply-To: "[hidden email]" <[hidden email]>
>     > >Date: Monday, May 22, 2017 at 10:03 AM
>     > >To: "[hidden email]" <[hidden email]>
>     > >Subject: Re: Recording stops due to HSTS
>     > >
>     > >Am 12.05.2017 um 11:21 schrieb Amarendra Darisa:
>     > >Hi,
>     > >
>     > >I am trying to record a transaction but hit a page which says is
> using
>     > >HSTS. It doesn’t allow me add an exception. As i am on mac, i double
>     > >checked the jMeter cert permissions again which seem to be fine.
> Please
>     > >suggest how to get this issue resolved. I am doing this on mac with
>     > >chrome browser.
>     > >Have you imported the generated JMeter testing certificate into your
>     > >browser? I had no problem accessing the site through JMeter's proxy
>     > >(when I imported the cert  ApacheJMeterTemporaryRootCA.crt from the
>     > >bin/ directory)
>     > >
>     > >Regards,
>     > > Felix
>     > >
>     > >
>     > >
>     > >[cid:image001.png@01D2D2F1.D87FC850]
>     > >
>     > >- Amar
>     >
>     > ------------------------------------------------------------
> ---------
>     > To unsubscribe, e-mail: [hidden email]
>     > For additional commands, e-mail: [hidden email]
>     >
>     >
>
>
>     --
>     Cordialement.
>     Philippe Mouawad.
>
>
>