Java: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

The problem appears when your server has self signed certificate. To workaround it you can add this certificate to the list of trusted certificates of your JVM. In this article author describes how to fetch the certificate from your browser and add it to cacerts file of your JVM. You can either edit JAVA_HOME/jre/lib/security/cacerts file … Read more

How can I see the entire HTTP request that’s being sent by my Python application?

A simple method: enable logging in recent versions of Requests (1.x and higher.) Requests uses the http.client and logging module configuration to control logging verbosity, as described here. Demonstration Code excerpted from the linked documentation: import requests import logging # These two lines enable debugging at httplib level (requests->urllib3->http.client) # You will see the REQUEST, … Read more

HTTP vs HTTPS performance

There’s a very simple answer to this: Profile the performance of your web server to see what the performance penalty is for your particular situation. There are several tools out there to compare the performance of an HTTP vs HTTPS server (JMeter and Visual Studio come to mind) and they are quite easy to use. … Read more

Why am I suddenly getting a “Blocked loading mixed active content” issue in Firefox?

I found this blog post which cleared up a few things. To quote the most relevant bit: Mixed Active Content is now blocked by default in Firefox 23! What is Mixed Content? When a user visits a page served over HTTP, their connection is open for eavesdropping and man-in-the-middle (MITM) attacks. When a user visits … Read more

How to create an HTTPS server in Node.js?

The Express API doc spells this out pretty clearly. Additionally this answer gives the steps to create a self-signed certificate. I have added some comments and a snippet from the Node.js HTTPS documentation: var express = require(‘express’); var https = require(‘https’); var http = require(‘http’); var fs = require(‘fs’); // This line is from the … Read more

How do I disable the security certificate check in Python requests

From the documentation: requests can also ignore verifying the SSL certificate if you set verify to False. >>> requests.get(‘https://kennethreitz.com’, verify=False) <Response [200]> If you’re using a third-party module and want to disable the checks, here’s a context manager that monkey patches requests and changes it so that verify=False is the default and suppresses the warning. … Read more

Is a HTTPS query string secure?

Yes, it is. But using GET for sensitive data is a bad idea for several reasons: Mostly HTTP referrer leakage (an external image in the target page might leak the password[1]) Password will be stored in server logs (which is obviously bad) History caches in browsers Therefore, even though Querystring is secured it’s not recommended … Read more

Trusting all certificates using HttpClient over HTTPS

You basically have four potential solutions to fix a “Not Trusted” exception on Android using httpclient: Trust all certificates. Don’t do this, unless you really know what you’re doing. Create a custom SSLSocketFactory that trusts only your certificate. This works as long as you know exactly which servers you’re going to connect to, but as … Read more