Skip to content

TLS & certificates

Every https:// request is encrypted with TLS. Zorvik checks the server’s certificate the way your browser does, and shows you what was negotiated.

By default Zorvik verifies that the server’s certificate chain leads to a trusted root and that the certificate matches the host name.

Trusted roots come from your operating system’s trust store:

SystemTrust store
WindowsThe Windows certificate store
macOSThe keychain
LinuxThe system’s CA certificates

So certificate authorities your company installs on your computer, for example for TLS inspection by a corporate proxy, are trusted without any setup in Zorvik.

Zorvik speaks TLS 1.2 and TLS 1.3. Older versions (TLS 1.0, TLS 1.1 and SSL) are not supported. HTTP/3 always uses TLS 1.3.

For servers whose certificates come from a private or self-signed certificate authority that isn’t in your OS trust store:

  1. Open Settings → Certificates.
  2. Under Extra CA certificate, choose Browse… and pick the CA’s certificate, or type its path.
  3. Choose Save.
SettingDetail
FormatPEM (-----BEGIN CERTIFICATE-----). One file can hold several certificates.
EffectTrusted in addition to the OS trust store, which stays in use
ScopeEvery request, in every workspace
ChangesZorvik notices when the file changes on disk

To trust the CA everywhere on your computer (browsers, curl, other tools) install it in your OS trust store instead; Zorvik then trusts it with no extra setting.

Some servers ask the client for a certificate too. To send one:

  1. Open Settings → Certificates.
  2. Client certificate: the PEM certificate. The file may also contain intermediate certificates after yours.
  3. Client key: the PEM private key for that certificate.
  4. Choose Save.
RuleDetail
Both or neitherSet both files. With only one, requests fail with Client certificate and client key must both be set for mutual TLS.
Key formatAn unencrypted PEM private key: PKCS#8 (BEGIN PRIVATE KEY), PKCS#1 RSA (BEGIN RSA PRIVATE KEY) or SEC1 EC (BEGIN EC PRIVATE KEY). Keys protected by a passphrase are not supported.
ScopeThe certificate is offered to every server that asks for a client certificate, in every workspace. There is no per-host setting.

Clear next to a path removes it.

For a test server with a self-signed certificate that you trust, you can skip verification:

  • For one request: the request’s Settings tab → Verify TLS certificates → Off. App default follows the global setting; On forces verification.
  • For every request: Settings → Requests → Verify TLS certificates.

With verification off, Zorvik accepts any certificate for any host name; the connection is still encrypted. The extra CA is not needed then, and client certificates are still sent.

In the request file
settings:
verifyTls: false

The certificate settings apply to every TLS connection Zorvik makes as a client:

  • HTTPS requests, including GraphQL and HTTP/3
  • WebSocket (wss://), Socket.IO and GraphQL subscriptions over TLS, event streams, gRPC (grpcs://), TCP over TLS, MQTT over TLS (mqtts://), DNS over TLS and DNS over HTTPS
  • OAuth 2.0 token requests and OpenAPI imports from a URL
  • Load tests

WebSocket, Socket.IO, event stream, gRPC, TCP and MQTT requests have the same Verify TLS certificates setting in their Settings tab.

A lock next to the status means the response came over TLS. The response’s Info tab lists, under Security:

FieldExample
TLSTLS 1.3
CipherTLS13_AES_128_GCM_SHA256
ALPNh2, http/1.1 or h3 (the negotiated application protocol)
SubjectThe server certificate’s subject
IssuerWho issued it
ValidFrom and until dates
NamesThe subject alternative names (host names and IP addresses)
SerialThe serial number

A plain http:// response shows TLS: Not encrypted. The Timing tab shows how long the TLS handshake took.

For a full certificate chain, expiry warnings and the protocol versions and ciphers a server accepts, use the TLS inspector in the Tools section of the left rail.

A failed handshake shows TLS / certificate error with the reason and a hint:

Message containsMeaningWhat to do
The certificate is not trusted (UnknownIssuer)The chain doesn’t lead to a trusted rootAdd the CA as Extra CA certificate, or install it in your OS trust store
The certificate does not match the host nameThe certificate is for other namesUse a host name listed under Names, or fix the certificate
The certificate has expiredIts validity endedRenew the certificate

Open settings in the error takes you to Settings. See also Troubleshooting.