SSL Configuration for Private Locations¶
By default, escape-cli uses your machine's system trust store, or the container's trust store when it's running in a container.
These settings apply to the agent's HTTPS calls to the Escape API, for example behind a TLS-inspecting proxy. They don't configure TLS trust for your scan targets.
See Environment Variables for the defaults and the complete TLS configuration reference.
Allowing Insecure SSL Connections¶
Set ESCAPE_SSL_INSECURE="true" to skip TLS certificate verification for the agent's HTTPS API calls.
Configuring Custom SSL CA Certificates¶
Set ESCAPE_SSL_CERT_PATH to a PEM bundle of trusted CA certificates. This replaces the system roots, so the bundle must include every CA needed to reach public.escape.tech through your network.
Single CA Certificate¶
To use a single CA certificate, set ESCAPE_SSL_CERT_PATH to its file path:
services:
private-location:
image: escapetech/cli:latest
environment:
- ESCAPE_API_KEY=<ESCAPE_API_KEY>
- ESCAPE_SSL_CERT_PATH=/certs/custom-ca.pem
volumes:
- ./certs:/certs
Multiple CA Certificates¶
The ESCAPE_SSL_CERT_PATH variable supports PEM files containing multiple CA certificates. To configure multiple CA certificates, concatenate them into a single PEM file with each certificate in standard PEM format:
-----BEGIN CERTIFICATE-----
MIIDXTCCAkWgAwIBAgIJAKJ...
(first CA certificate)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEBzCCAu+gAwIBAgICEA...
(second CA certificate)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFBjCCA+6gAwIBAgIQdY...
(third CA certificate)
-----END CERTIFICATE-----
Then reference this combined certificate file:
services:
private-location:
image: escapetech/cli:latest
environment:
- ESCAPE_API_KEY=<ESCAPE_API_KEY>
- ESCAPE_SSL_CERT_PATH=/certs/combined-ca-bundle.pem
volumes:
- ./certs:/certs
Certificate Management
When working with multiple CA certificates, maintain them in a single PEM bundle file rather than trying to specify multiple paths. The Private Location automatically parses and loads all certificates present in the specified file.