microsoft / microsoft/vscode-edge-devtools

Launched Edge browser does not inherit Windows certificate trust store — custom CA roots rejected

Open
#4,704 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
827
Forks
358
Avg merge
20h 32m
Merged PRs (30d)
10

Description

Environment

  • OS: Windows 10/11 (enterprise, domain-joined)
  • Extension version: latest
  • VS Code: 1.90+
  • Context: Corporate environment with internal CA / SSL inspection proxy (e.g. Zscaler, Cisco Umbrella)

Description

When the extension launches a headless or visible Edge instance via puppeteer, the browser is spawned with a fresh --user-data-dir (temporary profile by default). In some corporate environments using SSL-inspection proxies, an internally-trusted root CA is required to authenticate HTTPS connections. Puppeteer-launched Edge instances may not pick up the Windows certificate trust store correctly under all scenarios, especially when combined with --headless mode or a custom --user-data-dir.

There is currently no documented workaround and no setting to pass --ignore-certificate-errors-spki-list or --trusted-certificate-file via extension config.

Steps to Reproduce

  1. In a Windows enterprise environment with SSL inspection (Zscaler / Cisco Umbrella / custom corporate CA).
  2. Launch the Edge DevTools preview; the extension starts Edge with a temp user data dir.
  3. Navigate to an HTTPS target URL — certificate validation fails with ERR_CERT_AUTHORITY_INVALID.
  4. The extension provides no diagnostic or workaround guidance.

Expected Behavior

  • Document that users can pass --ignore-certificate-errors-spki-list or configure a user data dir pointing to a profile with trusted CAs via vscode-edge-devtools.userDataDir.
  • Alternatively, detect Windows cert store and pass it to the launched instance automatically.

Actual Behavior

No certificate guidance exists in the README or settings descriptions. Users face opaque SSL errors.

Workaround (undocumented)

Set vscode-edge-devtools.userDataDir to a stable Edge profile that already trusts the corporate CA, or add --ignore-certificate-errors-spki-list=<SPKI hash> via browserArgs.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the README and settings descriptions, then trace the handling of vscode-edge-devtools.userDataDir and browserArgs. Reproduce the Windows certificate failure with a temporary profile, headless Edge, and a corporate CA if available. Done means the supported certificate workaround and its configuration are clearly documented, with any relevant diagnostic guidance included.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript, vscode
Domain
devtools, documentation, tooling
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
62/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.