Skip to content

Configuration: Self Signed SSL Certificate

Identifier: self_signed_ssl

Scanner Support

GraphQL Scanner REST Scanner WebApp Scanner ASM Scanner Automated Pentest

Description

Self-signed SSL certificates aren't issued by a certificate authority and don't provide trust value, potentially making connections vulnerable to man-in-the-middle attacks.

How we test: We analyze SSL/TLS certificates to detect if they are self-signed by checking if certificates are issued by recognized certificate authorities. We verify certificate chain of trust and identify if self-signed certificates are being used.

Reference:

Configuration

Example

Example configuration:

---
security_tests:
  self_signed_ssl:
    skip: false

Reference

skip

Type: boolean

Skip the test if true.