srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2026-06-16 22:57:00 +0200
committersrdusr <[email protected]>2026-06-16 22:57:00 +0200
commit23c8ab359c2108654d57176e233d2c099b398f31 (patch)
tree3e2d1c66d987b4b771da69e67bd8a0c9ad2fc3db /README.md
parent6114567258bcad0517a0d881168711aaacdba5d5 (diff)
downloadmitmux-23c8ab359c2108654d57176e233d2c099b398f31.tar.gz
mitmux-23c8ab359c2108654d57176e233d2c099b398f31.zip
Client (mutual-TLS) certificates
Adds internal/clientcert: a cert/key pair matched to hosts by the same substring-or-regex pattern model as scope.Rule, so mitmux can present a client certificate on an upstream TLS handshake that requires one - the previous behavior was a hard handshake failure with no way to authenticate. Wired into both places mitmux dials an https:// upstream over its own TLS client connection: proxy.go's handleConnect (live proxied traffic) and repeat.go's dialForRepeat (Repeater/Intruder resends), both through a new Server.clientCertFor(host) helper. Stored in a new client_certs table, mirroring the existing scope_rules persistence pattern. The TUI (`t` from history) is add-only like scope, for the same reason: delete and re-add covers changing anything, and it's a rarely-touched, low-cardinality list. The add form takes cert/key file paths and reads them once at save time - PEM content, not the path, is what's stored and later presented, so a cert keeps working even if the original file moves afterward. Verified live against a real mutual-TLS-requiring origin server: without a matching cert the handshake correctly fails; with one configured, the origin receives it and the request succeeds; toggling it off reproduces the failure, confirming the enable/disable path works end to end.
Diffstat (limited to 'README.md')
-rw-r--r--README.md30
1 files changed, 24 insertions, 6 deletions
diff --git a/README.md b/README.md
index 4d424e6..b1237f6 100644
--- a/README.md
+++ b/README.md
@@ -49,11 +49,14 @@ list of what's deliberately not implemented (and why), see
sent) and grep-match/grep-extract (flag or pull text out of each
result's response with a regexp) are both configurable before starting
an attack - see [Intruder](#intruder) below.
-- **Match-and-replace**: header rewrite rules (add, remove, or modify)
- for requests and/or responses, applied live as traffic passes
- through. History still shows what was actually sent/received on each
- side - match-and-replace transforms the wire, it doesn't rewrite the
- audit trail.
+- **Match-and-replace**: header or body rewrite rules (add, remove, or
+ modify) for requests and/or responses, applied live as traffic
+ passes through. History still shows what was actually sent/received
+ on each side - match-and-replace transforms the wire, it doesn't
+ rewrite the audit trail.
+- **Client certificates**: configure a mutual-TLS cert/key per host
+ pattern, presented automatically on matching handshakes - for
+ proxied traffic and Repeater/Intruder resends alike.
- **Flagging**: mark an entry to revisit later (★), filterable via
`flagged:true`.
- **Comparer**: mark one entry (`c`), then `c` on a different entry to
@@ -442,6 +445,22 @@ Repeater and Intruder always record regardless of scope - a request you
deliberately resend or fuzz is something you clearly want to see the
result of, not noise scope exists to cut.
+### Client (mutual-TLS) certificates
+
+Press `t` from the history view to manage which client certificate
+mitmux presents when an upstream server's TLS handshake requests one
+- a target requiring mutual TLS otherwise fails the handshake before
+any request/response ever happens. `a` adds one: a name, a host
+pattern (same substring-or-regex model as scope and match-and-replace
+rules), and paths to a PEM certificate file and its matching PEM
+private key. The files are read once, at save time, and their content
+- not the paths - is what's stored and later presented, so a cert
+keeps working even if the original file moves or is deleted
+afterward. `space` toggles one on/off, `d` deletes it. Applies to
+proxied HTTPS traffic and to Repeater/Intruder resends against
+`https://` targets alike; a host matching no configured certificate
+just handshakes without one, same as if this feature didn't exist.
+
### Mouse
This is a real terminal application (any terminal, not just tmux - the
@@ -538,7 +557,6 @@ reasoning behind each:
- `mitmuxd -install-ca` prints per-OS trust-store install steps; it
never runs them for you (see Quick start above for why)
- No WebSocket interception
-- No client (mutual-TLS) certificate support
- Upstream proxy chaining (`-upstream-proxy`) is HTTP CONNECT only, no
SOCKS5
- No active or passive vulnerability scanning, no plugin system - this