Blog | G5 Cyber Security

Fiddler: Decrypting HTTPS with Elliptic Curves & Client Certificates

TL;DR

Yes, Fiddler can decrypt HTTPS traffic even when using elliptic curves and client certificate authentication. However, it requires specific configuration steps to import the root CA certificate used by your server and configure Fiddler to act as a trusted intermediary for both server and client certificates.

Steps

  1. Understand the Setup
  • Export Fiddler’s Root Certificate
  • Install Fiddler’s Root Certificate on the Server
  • Install Fiddler’s Root Certificate on the Client Machine(s)
  • Configure Fiddler to Decrypt Client Certificates
  • Configure Fiddler to Handle Client Certificate Authentication
  • Verify Decryption
  • Troubleshooting

    Exit mobile version