client certificate in plain text (any way to obfuscate it)

9 views
Skip to first unread message

Christopher Williams

unread,
Aug 12, 2021, 12:33:22 PM8/12/21
to OWASP ZAP Developer Group
Hi everyone,

I've successfully created a context including an authenticated user using (PKCS#12) file and proper user setup. 

I've integrated the user into a jenkins pipeline and am calling full scan via the public docker image. 

In my environment I'd prefer not to use the a plain text password for the certificate

certificate.pkcs12.password=WhateverThePasswordIs

Is this possible ? 

kingthorin+owaspzap

unread,
Aug 12, 2021, 1:37:52 PM8/12/21
to OWASP ZAP Developer Group
That's up to your setup, if you can handle it via an env var or key vault interaction.
Reply all
Reply to author
Forward
0 new messages