[ grinder-Bugs-3517740 ] TCPProxy - bad_certificate exceptions

SourceForge.net <[email protected]> Fri, 04 May 2012 09:11:58 -0700
Newsgroups gmane.comp.java.grinder.devel
Message-ID <[email protected]>
Bugs item #3517740, was opened at 2012-04-14 05:45
Message generated for change (Comment added) made by philipa
You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=118598&aid=3517740&group_id=18598

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: TCPProxy
Group: None
Status: Open
Resolution: None
Priority: 4
Private: No
Submitted By: Philip Aston (philipa)
Assigned to: Philip Aston (philipa)
Summary: TCPProxy - bad_certificate exceptions

Initial Comment:
Using the TCPProxy to record a trivial script against HTTPS google produces exceptions such as:

15:42:28.988 [Filter thread for localhost.localdomain:35619->ssl.gstatic.com:443] ERROR: Received fatal alert: bad_certificate
javax.net.ssl.SSLHandshakeException: Received fatal alert: bad_certificate
	at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Alerts.java:174) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Alerts.java:136) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.recvAlert(SSLSocketImpl.java:1694) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:939) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.waitForClose(SSLSocketImpl.java:1467) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.HandshakeOutStream.flush(HandshakeOutStream.java:103) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.Handshaker.sendChangeCipherSpec(Handshaker.java:625) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.ServerHandshaker.sendChangeCipherAndFinish(ServerHandshaker.java:1170) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.ServerHandshaker.clientFinished(ServerHandshaker.java:1130) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.ServerHandshaker.processMessage(ServerHandshaker.java:223) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.Handshaker.processLoop(Handshaker.java:529) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.Handshaker.process_record(Handshaker.java:465) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(SSLSocketImpl.java:884) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(SSLSocketImpl.java:1120) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readDataRecord(SSLSocketImpl.java:744) ~[na:1.6]
	at com.sun.net.ssl.internal.ssl.AppInputStream.read(AppInputStream.java:75) ~[na:1.6]
	at net.grinder.tools.tcpproxy.AbstractTCPProxyEngine$FilteredStreamThread.interruptibleRun(AbstractTCPProxyEngine.java:431) ~[classes/:na]
	at net.grinder.util.thread.InterruptibleRunnableAdapter.run(InterruptibleRunnableAdapter.java:58) [classes/:na]
	at java.lang.Thread.run(Thread.java:619) [na:1.6.0_21]

This is an error from the google server, but what cert is the TCPProxy sending, and why?

----------------------------------------------------------------------

>Comment By: Philip Aston (philipa)
Date: 2012-05-04 09:11

Message:
After nearly going blind staring at wireshark, I've figured this out.

Its simply that FireFox does not prompt for certificates it doesn't trust
that aren't securing the URL of the primary resource.

Its possible to configure FF manually to trust the grinder certificate for
these secondary URLs. Confure FF so everything goes through the TCPProxy.
Go to Preferences/Advanced/Encryption/View Certificates/Servers, and select
"Add Exception". Type the URL into the location bar (e.g.
https://ssl.gstatic.com) and then select "Get Certificate". You can then
chose to confirm the exception.

----------------------------------------------------------------------

You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=118598&aid=3517740&group_id=18598

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/