# Problems with SSL in Gatling Recorder

**URL:** <https://community.gatling.io/t/problems-with-ssl-in-gatling-recorder/596>\
**Category:** Gatling (Open-Source)\
**Created:** [September 24, 2013, 5:44pm UTC](https://community.gatling.io/t/problems-with-ssl-in-gatling-recorder/596 "2013-09-24T17:44:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hank](https://avatars.discourse-cdn.com/v4/letter/h/f475e1/32.png) [@Hank](https://community.gatling.io/u/Hank)\
**Post date:** [September 24, 2013, 5:44pm UTC](https://community.gatling.io/t/problems-with-ssl-in-gatling-recorder/596/1 "2013-09-24T17:44:13Z")

</div>

Hi, I’m having problems with SSL in Gatling Recorder. I’m using Firefox in Mac OS X (because it allows me to use custom proxy settings). When I attempt to navigate to a secured site, I get a “This Connection is Untrusted” warning. Viewing the technical details gives the following message:

[www.github.com](http://www.github.com) uses an invalid security certificate.

The certificate is not trusted because it is self-signed.  
The certificate is only valid for Gatling

(Error code: sec\_error\_ca\_cert\_invalid)

When I attempt to add an exception, I receive a “No Information Available” message, and there’s no way for me to confirm the security exception or import the gatling certificate. The following exception appears in my terminal window.

10:39:20.765 [WARN] i.g.r.h.h.BrowserHttpsRequestHandler - Trying to connect to [https://www.github.com:443](https://www.github.com:443), make sure you’ve accepted the recorder certificate for this site  
10:39:20.783 [ERROR] i.g.r.h.h.BrowserHttpsRequestHandler - Exception caught  
javax.net.ssl.SSLException: Received fatal alert: bad\_certificate  
at sun.security.ssl.Alerts.getSSLException(Alerts.java:208) ~[na:1.7.0\_21]  
at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1619) ~[na:1.7.0\_21]  
at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1587) ~[na:1.7.0\_21]  
at sun.security.ssl.SSLEngineImpl.recvAlert(SSLEngineImpl.java:1756) ~[na:1.7.0\_21]  
at sun.security.ssl.SSLEngineImpl.readRecord(SSLEngineImpl.java:1060) ~[na:1.7.0\_21]  
at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:884) ~[na:1.7.0\_21]  
at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:758) ~[na:1.7.0\_21]  
at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624) ~[na:1.7.0\_21]  
at org.jboss.netty.handler.ssl.SslHandler.unwrap(SslHandler.java:1225) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.handler.ssl.SslHandler.decode(SslHandler.java:913) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.handler.codec.frame.FrameDecoder.callDecode(FrameDecoder.java:425) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.handler.codec.frame.FrameDecoder.messageReceived(FrameDecoder.java:303) ~[netty-3.6.6.Final.jar:na]  
at io.gatling.recorder.http.ssl.FirstEventIsUnsecuredConnectSslHandler.handleUpstream(FirstEventIsUnsecuredConnectSslHandler.scala:31) ~[gatling-recorder-2.0.0-M3a.jar:na]  
at org.jboss.netty.channel.Channels.fireMessageReceived(Channels.java:268) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.channel.Channels.fireMessageReceived(Channels.java:255) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.channel.socket.nio.NioWorker.read(NioWorker.java:88) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.channel.socket.nio.AbstractNioWorker.process(AbstractNioWorker.java:109) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.channel.socket.nio.AbstractNioSelector.run(AbstractNioSelector.java:312) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.channel.socket.nio.AbstractNioWorker.run(AbstractNioWorker.java:90) ~[netty-3.6.6.Final.jar:na]  
at org.jboss.netty.channel.socket.nio.NioWorker.run(NioWorker.java:178) ~[netty-3.6.6.Final.jar:na]  
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145) [na:1.7.0\_21]  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615) [na:1.7.0\_21]  
at java.lang.Thread.run(Thread.java:722) [na:1.7.0\_21]

I’m using gatling-charts-highcharts-2.0.0-M3a-bundle. I’ve tried using the Mac OS X system proxy with both Google Chrome and Firefox and I’m getting the same behavior there. Any suggestions for getting this to work?

Thanks,  
Hank

---

<div class="post-metadata">

**Author:** ![Excilys](https://avatars.discourse-cdn.com/v4/letter/e/8797f3/32.png) [@Excilys](https://community.gatling.io/u/Excilys)\
**Post date:** [September 24, 2013, 6:54pm UTC](https://community.gatling.io/t/problems-with-ssl-in-gatling-recorder/596/2 "2013-09-24T18:54:53Z")

</div>

Hi,

You probably have to remove github’s certificate from Firefox’s keystore, as explained here: [https://github.com/excilys/gatling/wiki/Recorder#wiki-https](https://github.com/excilys/gatling/wiki/Recorder#wiki-https)

Cheers,

Stéphane

---

<div class="post-metadata">

**Author:** ![Hank](https://avatars.discourse-cdn.com/v4/letter/h/f475e1/32.png) [@Hank](https://community.gatling.io/u/Hank)\
**Post date:** [September 24, 2013, 8:23pm UTC](https://community.gatling.io/t/problems-with-ssl-in-gatling-recorder/596/3 "2013-09-24T20:23:50Z")

</div>

There doesn’t seem to be a certificate for github in the Firefox keystore - there’s a root certificate authority for DigiCert High Assurance EV CA-1, which is the authority that issues the Github certificate, but even deleting/distrusting that authority doesn’t change the certificate behavior in Firefox - I go to add an exception and it gives me the “No information available” error.

Is there perhaps a place where I can get the Gatling cert file so I can try manually adding it to my trusted certificates list?

Thanks,  
Hank

---

<div class="post-metadata">

**Author:** ![Excilys](https://avatars.discourse-cdn.com/v4/letter/e/8797f3/32.png) [@Excilys](https://community.gatling.io/u/Excilys)\
**Post date:** [September 24, 2013, 9:00pm UTC](https://community.gatling.io/t/problems-with-ssl-in-gatling-recorder/596/4 "2013-09-24T21:00:05Z")

</div>

Damn, this was possible a few weeks ago, Firefox probably changed that.

Until someone finds a solution, the only way I see is the HAR support: [https://github.com/excilys/gatling/wiki/Gatling-2#wiki-recorder](https://github.com/excilys/gatling/wiki/Gatling-2#wiki-recorder)

---

<div class="post-metadata">

**Author:** ![Excilys](https://avatars.discourse-cdn.com/v4/letter/e/8797f3/32.png) [@Excilys](https://community.gatling.io/u/Excilys)\
**Post date:** [September 26, 2013, 12:39pm UTC](https://community.gatling.io/t/problems-with-ssl-in-gatling-recorder/596/5 "2013-09-26T12:39:01Z")

</div>

I have no problems with other sites such as [https://www.secure.bnpparibas.net](https://www.secure.bnpparibas.net).

I won’t have the cycles to investigate this any time out. If you find out the reason why it doesn’t work for github, please let us know.

Regards,

Stéphane
