As mobile app penetration testers, we often rely on Burp Suite to intercept HTTPS traffic from Android applications. However, as security hardening has improved in the Android ecosystem, many apps now implement SSL pinning or certificate blacklisting, rendering traditional interception methods ineffective.
If you’ve ever tried installing Burp’s default certificate on your Android device only to find that HTTPS requests are still blocked, you’re not alone. Many modern apps now check for known certificate authorities like PortSwigger (Burp Suite’s CA) and block connections if such certs are detected.
This post explains how to bypass this limitation by generating a custom certificate using a Python script (customca.py) that integrates OpenSSL commands, allowing for effective HTTPS traffic interception even on hardened apps.
The Problem with Burp Suite’s Default Certificate
When Burp Suite generates its CA certificate, it includes the issuer name PortSwigger and common default metadata in the certificate fields. Many Android applications today use static or dynamic certificate pinning techniques that:
- Verify the certificate chain.
- Check the common name (CN) or issuer (O/OU) fields.
- Compare the public key or hash of the expected cert with the one being used.
If the app sees PortSwigger or a mismatched public key, it simply refuses the connection.
Even if the Burp certificate is installed in the system trust store, the app may still reject it due to pinning or blacklisting.
The Solution: Custom Certificates
To bypass such restrictions, the idea is simple:
Use your own OpenSSL certificate that mimics a legitimate CA with your own name, not Burp Suite.
By customizing the:
- Common Name (CN)
- Organization (O)
- Organizational Unit (OU)
…you avoid the known fingerprints that apps might check against.
That’s exactly what customca.py does.
How the customca.py Script Works
The script automates the entire process of generating a self-signed RSA certificate, and then converts it into DER and PKCS#8 formats for compatibility with:
- Burp Suite’s certificate import requirements
- Android’s trusted CA installation steps
Steps automated in the script:
Generate RSA Private Key & Certificate (PEM):
openssl req -x509 -days 825 -newkey rsa:2048 -nodes -keyout your.key -out your.crt
Convert to DER Format (for Burp):
openssl x509 -in your.crt -outform der -out your.der
Convert Private Key to PKCS#8 (for Burp):
openssl pkcs8 -topk8 -inform der -in your_key.der -outform der -nocrypt -out your_key.pkcs8.der
Installing on Android & Configuring Burp
Once generated, install the .crt on your Android device as a trusted CA:
Settings > Security > Encryption & Credentials > Install a Certificate
Choose CA Certificate and select your custom .crt file
Confirm installation (set screen lock if needed)
Then, in Burp Suite, go to:
Proxy > Options > Import / Export CA Certificate
Import your .der certificate and .pkcs8.der key as the CA.
Testing the Setup
To confirm it’s working:
Route your Android device’s Wi‑Fi through Burp Suite (proxy setup)
Intercept an HTTPS request
If you see traffic in Burp and no SSL errors in the app — you’ve successfully bypassed SSL pinning or certificate blacklisting!
What About Apps Using Strong SSL Pinning?
Some apps use advanced techniques such as:
- Pinned public key hashes
- Native SSL verification in compiled libraries (e.g., with okhttp, trustkit, etc.)
- Certificate Transparency logs
- Certificate fingerprint comparison using TrustManager
In such cases, this method alone may not work. You’ll need to combine it with tools like:
- Frida (to hook SSL functions)
- Magisk modules (like TrustMeAlready, MagiskTrustUserCerts)
- Xposed Framework (with modules like JustTrustMe, SSLUnpinning)
Still, for many apps that only blacklist PortSwigger or basic CAs — this custom certificate method is enough.
Conclusion
Using a custom OpenSSL certificate can effectively bypass basic SSL pinning and certificate blacklisting mechanisms in Android apps, giving you access to HTTPS traffic for testing and analysis.
Whether you’re a bug bounty hunter or a mobile pentester, this script can save you time and frustration. Try It Out
View the script on GitHub:
https://github.com/im-whoami/burpcustomcert




