Skip to content
Windows

WePROXA 3.0.0 now supports Windows and macOS. Windows installation is available from the Microsoft Store.

Certificate Trust

To intercept HTTPS traffic on macOS, WePROXA generates a local root Certificate Authority (CA) and trusts it in macOS Keychain. This lets WePROXA decrypt, inspect, and re-encrypt HTTPS traffic for the hosts or apps you explicitly enable.

When WePROXA starts, it automatically generates a root CA certificate unique to your machine. To intercept HTTPS traffic, you must install and trust this certificate.

  1. Open WePROXA and go to SettingsCA Certificate.
  2. Click Install to macOS.
  3. Enter your macOS password when prompted. The certificate is installed in the System keychain and marked as trusted for SSL/TLS connections.

WePROXA CA Certificate settings

After this one-time setup, HTTPS interception works seamlessly.

The Certificates settings show a live Trust status for the local CA so you always know whether HTTPS can be decrypted:

  • Installed & trusted — the certificate is in Keychain and set to trust SSL/TLS. Interception is ready.
  • Not trusted yet — the certificate exists but is not installed or trusted. Install it to inspect HTTPS.
  • Set to “Never Trust” — the certificate is explicitly distrusted in Keychain, which blocks interception until you re-enable trust.

If SSL interception is enabled while the certificate is not trusted, WePROXA warns you that HTTPS won’t be decrypted until you install it.

When the certificate still needs attention, WePROXA can walk you through fixing it instead of sending you to Keychain unaided:

  • If it is not trusted yet, an Install & Trust action installs and trusts the certificate in one step.
  • If it is set to “Never Trust”, the dialog explains how to switch it back to Always Trust in Keychain Access.

You can reopen these steps at any time from the certificate menu or the Certificate settings link.

If you need to manually trust the certificate:

  1. Open Keychain Access from Spotlight.
  2. Find the WePROXA Root CA certificate in the System keychain, or in the login keychain if it was installed for the current user only.
  3. Double-click it and expand Trust.
  4. Set Secure Sockets Layer (SSL) to Always Trust.
  5. Close the window and enter your password to confirm.

The Certificate lifecycle controls in SettingsCA Certificate let you manage the local CA directly from WePROXA:

  • Generate certificate — create a new local CA when none exists yet.
  • Regenerate certificate — replace the CA identity and private key. HTTPS inspection stops working until the new certificate is installed and trusted again on every device.
  • Download certificate — save the CA certificate to a file, for example to trust it on another device.
  • Remove local certificate — permanently delete WePROXA’s local CA certificate and private key.

The quickest way to remove the CA is the Remove local certificate action described above. To also delete copies from Keychain (or to remove a certificate installed by an older version):

  1. Open Keychain Access.
  2. Search for WePROXA.
  3. Right-click the certificate and select Delete.
  • The CA certificate is generated locally and never leaves your machine
  • The private key is stored securely in the app’s data directory
  • Each installation generates a unique certificate
  • Removing WePROXA also removes the ability to impersonate any site