Skip to content

SSL Configuration for Private Locations

By default, escape-cli uses your machine's system trust store, or the container's trust store when it's running in a container.

These settings apply to the agent's HTTPS calls to the Escape API, for example behind a TLS-inspecting proxy. They don't configure TLS trust for your scan targets.

See Environment Variables for the defaults and the complete TLS configuration reference.

Allowing Insecure SSL Connections

Set ESCAPE_SSL_INSECURE="true" to skip TLS certificate verification for the agent's HTTPS API calls.

Configuring Custom SSL CA Certificates

Set ESCAPE_SSL_CERT_PATH to a PEM bundle of trusted CA certificates. This replaces the system roots, so the bundle must include every CA needed to reach public.escape.tech through your network.

Single CA Certificate

To use a single CA certificate, set ESCAPE_SSL_CERT_PATH to its file path:

services:
  private-location:
    image: escapetech/cli:latest
    environment:
      - ESCAPE_API_KEY=<ESCAPE_API_KEY>
      - ESCAPE_SSL_CERT_PATH=/certs/custom-ca.pem
    volumes:
      - ./certs:/certs

Multiple CA Certificates

The ESCAPE_SSL_CERT_PATH variable supports PEM files containing multiple CA certificates. To configure multiple CA certificates, concatenate them into a single PEM file with each certificate in standard PEM format:

-----BEGIN CERTIFICATE-----
MIIDXTCCAkWgAwIBAgIJAKJ...
(first CA certificate)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEBzCCAu+gAwIBAgICEA...
(second CA certificate)
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIFBjCCA+6gAwIBAgIQdY...
(third CA certificate)
-----END CERTIFICATE-----

Then reference this combined certificate file:

services:
  private-location:
    image: escapetech/cli:latest
    environment:
      - ESCAPE_API_KEY=<ESCAPE_API_KEY>
      - ESCAPE_SSL_CERT_PATH=/certs/combined-ca-bundle.pem
    volumes:
      - ./certs:/certs

Certificate Management

When working with multiple CA certificates, maintain them in a single PEM bundle file rather than trying to specify multiple paths. The Private Location automatically parses and loads all certificates present in the specified file.