MITM certificates and HTTPS rewriting
For iPhone / iPad. Ordinary proxy access does not require MITM.
Install and trust
- Open Settings → MITM → MITM Certificates and inspect This Device.
- If no certificate exists, choose Generate Certificate. To share an existing account certificate with another device, use the account-certificate controls instead.
- Choose Install Trust Profile and complete profile installation in iOS Settings.
- Under General → About → Certificate Trust Settings, enable full trust for that root certificate.
- Return to the app, enable MITM as prompted, and check the intended hosts and rules.
Replacing the local certificate requires installing and trusting the new one; an old installed profile will not trust it. Regenerating certificates is not a general fix for connection failures.
Installing the profile and trusting its root are separate steps. See Apple's certificate-trust instructions.
Enable and verify rules
Review imported hosts and scripts. Remote MITM rule sets start disabled. Enable only the required sets and keep host scope narrow. HTTPS module rewriting also needs the master switch, a trusted certificate and active module content.
Connect the VPN, reopen the service and inspect request details or MITM diagnostics. An imported rule alone does not prove interception.
| Symptom | Check |
|---|---|
| No match | Host scope and master/set/module switches |
| Certificate error | Installation, full trust and certificate pinning |
| A feature breaks | Disable the relevant set or module and compare |
Pinned applications may reject interception. Do not disable global certificate verification; exclude unsuitable hosts and retain their original TLS connection.
To stop, disable MITM or the relevant set and recreate connections. Remove the profile in system settings if no longer needed. Never share its private key.