# CA issue with client certificate

**URL:** <https://discourse.mitmproxy.org/t/ca-issue-with-client-certificate/810>\
**Category:** help\
**Created:** [January 25, 2018, 2:46pm UTC](https://discourse.mitmproxy.org/t/ca-issue-with-client-certificate/810 "2018-01-25T14:46:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gigiarum](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/gigiarum/32/278_2.png) [@Gigiarum](https://discourse.mitmproxy.org/u/Gigiarum)\
**Post date:** [January 25, 2018, 2:46pm UTC](https://discourse.mitmproxy.org/t/ca-issue-with-client-certificate/810/1 "2018-01-25T14:46:49Z")

</div>

I am using a client certificate but site responde me with 403 and I see in output this message:

> Certificate Verification Error for xxxxx.xxxxx.it: unable to get local issuer certificate (errno: 20, depth: 0)  
> Ignoring server verification error, continuing with connection  
> GET [https://xxxxx.xxxxx.it/](https://xxxxx.xxxxx.it/)  
> \<\< 403 Forbidden 142b

I understand that client certificate was not send to remote server. The certificate is not signed by a trusted CA, is it the problem? How can I force send it?

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [January 25, 2018, 2:57pm UTC](https://discourse.mitmproxy.org/t/ca-issue-with-client-certificate/810/2 "2018-01-25T14:57:46Z")

</div>

Hi, did you verify that mitmproxy is not sending a client certificate in e.g. Wireshark? How do you invoke mitmproxy?

---

<div class="post-metadata">

**Author:** ![Gigiarum](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/gigiarum/32/278_2.png) [@Gigiarum](https://discourse.mitmproxy.org/u/Gigiarum)\
**Post date:** [January 25, 2018, 3:14pm UTC](https://discourse.mitmproxy.org/t/ca-issue-with-client-certificate/810/3 "2018-01-25T15:14:51Z")

</div>

I call mitmdump with `--client-certs` option. I try two sites with two different client certificates and one is going well and the other with the problem I said.  
I do not try to verify with Wireshark: the warning I reported does not involve to client certificate not sent?

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [January 25, 2018, 4:38pm UTC](https://discourse.mitmproxy.org/t/ca-issue-with-client-certificate/810/4 "2018-01-25T16:38:48Z")

</div>

> [@Gigiarum](#):
>
> I do not try to verify with Wireshark: the warning I reported does not involve to client certificate not sent?

The “Ignoring server verification error, continuing with connection” warning only states that mitmproxy doesn’t trust the server certificate. You are probably passing --insecure because the connection would otherwise fail. Other than that, it’s a regular HTTP request with a 403 Forbidden response from mitmproxy’s perspective.

---

<div class="post-metadata">

**Author:** ![Gigiarum](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/gigiarum/32/278_2.png) [@Gigiarum](https://discourse.mitmproxy.org/u/Gigiarum)\
**Post date:** [February 1, 2018, 1:35pm UTC](https://discourse.mitmproxy.org/t/ca-issue-with-client-certificate/810/5 "2018-02-01T13:35:07Z")

</div>

It was my mistake, the client certificate was not send to server.
