[SSL Pinning Plugin] How to test if SSL Pinning is working
Forge component by OutSystems R&D
Published on 02 Sep 2020

I already implemented SSL Pinning , I just want to know how to check if its working so we could be free from findings during PEN Test.

Rank: #325


This is taken from SSL Pinning Plugin Documentation :

Test the SSL pinning

To test the mobile app with SSL Pinning, do the following:

  1. Publish and generate the new version of your mobile app with SSL Pinning.

  2. Install the app in your smartphone and run. 

  3. Verify that app works, as it has the right certificate and hash keys.

To see SSL pinning in rejecting a certificate, do the following:

  1. Edit the configuration file and tamper with the hashes. For example, change one character in each hash.

  2. In your mobile app:

    1. Remove the resource with the old configuration file.

    2. Add a resource with the new configuration file (don’t forget to set the properties).

    3. Publish and generate the new version.

  3. Install the new version in your smartphone and run.

  4. The mobile app won’t work because the SSL inning raises an error due to an invalid certificate.