Recreating certificates using Apostille
ID: 9f5057e7-0fcd-5ef7-93d7-b90adeebb3a1
STIX ID: report--9f5057e7-0fcd-5ef7-93d7-b90adeebb3a1
Feed Name: SensePost Blog
This report introduces Apostille, a tool that uses Java BouncyCastle to clone entire X.509 certificate chains by generating matching key pairs and reproducing certificate attributes and extensions, enabling realistic certificate chains for TLS interception and potential certificate pinning bypass in testing scenarios. It outputs PEM-encoded keys and certificates (and optionally a JKS), supports RSA/DSA/EC, and is designed for use with tools like Burp and Mallet, while noting operational considerations such as trust store manipulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
