diff options
| author | srdusr <[email protected]> | 2026-06-16 22:57:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-06-16 22:57:00 +0200 |
| commit | 23c8ab359c2108654d57176e233d2c099b398f31 (patch) | |
| tree | 3e2d1c66d987b4b771da69e67bd8a0c9ad2fc3db /README.md | |
| parent | 6114567258bcad0517a0d881168711aaacdba5d5 (diff) | |
| download | mitmux-23c8ab359c2108654d57176e233d2c099b398f31.tar.gz mitmux-23c8ab359c2108654d57176e233d2c099b398f31.zip | |
Client (mutual-TLS) certificates
Adds internal/clientcert: a cert/key pair matched to hosts by the same
substring-or-regex pattern model as scope.Rule, so mitmux can present
a client certificate on an upstream TLS handshake that requires one -
the previous behavior was a hard handshake failure with no way to
authenticate. Wired into both places mitmux dials an https:// upstream
over its own TLS client connection: proxy.go's handleConnect (live
proxied traffic) and repeat.go's dialForRepeat (Repeater/Intruder
resends), both through a new Server.clientCertFor(host) helper.
Stored in a new client_certs table, mirroring the existing scope_rules
persistence pattern. The TUI (`t` from history) is add-only like
scope, for the same reason: delete and re-add covers changing
anything, and it's a rarely-touched, low-cardinality list. The add
form takes cert/key file paths and reads them once at save time - PEM
content, not the path, is what's stored and later presented, so a
cert keeps working even if the original file moves afterward.
Verified live against a real mutual-TLS-requiring origin server:
without a matching cert the handshake correctly fails; with one
configured, the origin receives it and the request succeeds; toggling
it off reproduces the failure, confirming the enable/disable path
works end to end.
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 30 |
1 files changed, 24 insertions, 6 deletions
@@ -49,11 +49,14 @@ list of what's deliberately not implemented (and why), see sent) and grep-match/grep-extract (flag or pull text out of each result's response with a regexp) are both configurable before starting an attack - see [Intruder](#intruder) below. -- **Match-and-replace**: header rewrite rules (add, remove, or modify) - for requests and/or responses, applied live as traffic passes - through. History still shows what was actually sent/received on each - side - match-and-replace transforms the wire, it doesn't rewrite the - audit trail. +- **Match-and-replace**: header or body rewrite rules (add, remove, or + modify) for requests and/or responses, applied live as traffic + passes through. History still shows what was actually sent/received + on each side - match-and-replace transforms the wire, it doesn't + rewrite the audit trail. +- **Client certificates**: configure a mutual-TLS cert/key per host + pattern, presented automatically on matching handshakes - for + proxied traffic and Repeater/Intruder resends alike. - **Flagging**: mark an entry to revisit later (★), filterable via `flagged:true`. - **Comparer**: mark one entry (`c`), then `c` on a different entry to @@ -442,6 +445,22 @@ Repeater and Intruder always record regardless of scope - a request you deliberately resend or fuzz is something you clearly want to see the result of, not noise scope exists to cut. +### Client (mutual-TLS) certificates + +Press `t` from the history view to manage which client certificate +mitmux presents when an upstream server's TLS handshake requests one +- a target requiring mutual TLS otherwise fails the handshake before +any request/response ever happens. `a` adds one: a name, a host +pattern (same substring-or-regex model as scope and match-and-replace +rules), and paths to a PEM certificate file and its matching PEM +private key. The files are read once, at save time, and their content +- not the paths - is what's stored and later presented, so a cert +keeps working even if the original file moves or is deleted +afterward. `space` toggles one on/off, `d` deletes it. Applies to +proxied HTTPS traffic and to Repeater/Intruder resends against +`https://` targets alike; a host matching no configured certificate +just handshakes without one, same as if this feature didn't exist. + ### Mouse This is a real terminal application (any terminal, not just tmux - the @@ -538,7 +557,6 @@ reasoning behind each: - `mitmuxd -install-ca` prints per-OS trust-store install steps; it never runs them for you (see Quick start above for why) - No WebSocket interception -- No client (mutual-TLS) certificate support - Upstream proxy chaining (`-upstream-proxy`) is HTTP CONNECT only, no SOCKS5 - No active or passive vulnerability scanning, no plugin system - this |