--- title: 如何修改 Charles 以解密模拟器 HTTPS type: experience permalink: main/projects/280dd2a0-d23d-4a71-91e1-dce4353163be/如何修改-charles-以解密模拟器-https stable_id: 120e75c2-feea-450c-b525-5623768b318f scope: project memory_type: experience project_id: 280dd2a0-d23d-4a71-91e1-dce4353163be usage_profile_id: 0c9feb46-d06e-43cd-9ef0-c5813c84a998 status: active revision: 1 request_id: rapdrama-exp-charles-20260925-0346 created_at: '2026-09-24T19:48:51.330293+00:00' updated_at: '2026-09-24T19:48:51.330293+00:00' tags: - charles - ssl - 配置 --- Charles 配置文件是 %APPDATA%\\Charles\\charles.config。根证书在 %APPDATA%\\Charles\\data\\ca\\charles-proxy-ssl-proxying-certificate.pem。修改前先备份该文件(本次备份名 charles.config.bak-capture),并先结束 Charles 进程再写。Charles 运行中写入会在退出时被覆盖。未知 XML 字段会让 Charles 整份配置回退到默认值,连注册信息一起丢掉;曾因为写入不存在的 enableSOCKSTransparentHTTPProxying 发生过一次,已用备份恢复。启动后要确认 registrationConfiguration 还在、端口 8888 在监听。 已验证可以写入并被 Charles 5.2.1 保留的 proxyConfiguration: - port 8888 - enableSOCKSProxy false - decryptSSL true - transparentProxy true(后来为透明代理尝试打开;强制转发已撤销,这个开关仍留在配置里) - sslLocations → locationPatterns → locationMatch:location 的 host 为 *、port 为 *,enabled 为 true - windowsConfiguration:useHTTP false、useSOCKS false、enableAtStartup false 证书哈希用 Git 自带的 openssl 计算,不要用别的 adb: C:\\Program Files\\Git\\usr\\bin\\openssl.exe x509 -inform PEM -subject_hash_old -in 证书.pem -noout 当前这张根证书的 subject_hash_old 是 275d036d。把 PEM 复制为 275d036d.0。重置 Charles 根证书后哈希会变,需要重新计算并重装。不要把私钥或注册码写进记忆。 验证:用该 openssl 经代理连 example.com:443,-CAfile 指向这张 PEM,Verification 为 OK。电脑直连不到的主机(如 android.googleapis.com)会在 Charles 里显示 CONNECT 超时和 503,这不是证书失败。当时机器上有 Clash Verge 服务,但没有本地代理端口在监听,Charles 是直连出去的。