Enable unsafe SSL\TLS renegotiation via cmd

192 views
Skip to first unread message

Lia

unread,
Sep 23, 2023, 7:40:35 AM9/23/23
to ZAP User Group
Hi there,

Can I know how to enable Enable unsafe SSL\TLS renegotiation via cmd? 
How to set it using the "-config" parameter?

Thank you

Simon Bennetts

unread,
Sep 25, 2023, 4:20:09 AM9/25/23
to ZAP User Group

Lia

unread,
Sep 25, 2023, 6:03:55 AM9/25/23
to ZAP User Group
Hi Simon,

Yes, I actually referenced to that FAQ but I can't seem to find the SSL\TLS renegotiation in the config.xml.
I only see this under the connection:

<connection version="3">
            <defaultUserAgent>Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36</defaultUserAgent>
            <timeoutInSecs>180</timeoutInSecs>
            <useGlobalHttpState>false</useGlobalHttpState>
            <dnsTtlSuccessfulQueries>30</dnsTtlSuccessfulQueries>
            <httpProxy>
                <enabled>false</enabled>
                <authEnabled>false</authEnabled>
                <storePass>true</storePass>
                <password/>
            </httpProxy>
            <socksProxy>
                <enabled>false</enabled>
            </socksProxy>
            <tlsProtocols>
                <protocol>TLSv1.2</protocol>
                <protocol>TLSv1.3</protocol>
            </tlsProtocols>
        </connection>

Please share how to enable it via command line.
Thank you.

thc...@gmail.com

unread,
Sep 25, 2023, 6:08:25 AM9/25/23
to zaprox...@googlegroups.com
Did you enable the option?

Best regards.

Lia

unread,
Sep 25, 2023, 9:10:42 PM9/25/23
to ZAP User Group
Hi there,

Yup, I tried enabling the option in GUI and it appeared!
Thanks guys.

Reply all
Reply to author
Forward
0 new messages