HSTS or certificate pinning is a security policy to avoid man in the middle attacks. Sometimes you want to debug application with a proxy and HSTS will avoid the developer to debug the web application with firefox or chrome. In this short guide we explain how to disable certificate pinning for Firefox and Chrome.
How to Remove a pinned certificate from Firefox
- Quit Firefox
- Open the file named "SiteSecurityServiceState.txt" in the Firefox profile you are using. Default location is ~/.mozilla/firefox).
How to Remove a pinned certificate from Chrome
- Go to the URL chrome://net-internals/#hsts
- Now delete the related domain