MemRelay-Operation: memory-save:rapdrama-exp-charles-20260925-0346 MemRelay-Resource: 120e75c2-feea-450c-b525-5623768b318f
38 lines
2.3 KiB
Markdown
38 lines
2.3 KiB
Markdown
---
|
||
title: 如何修改 Charles 以解密模拟器 HTTPS
|
||
type: experience
|
||
permalink: main/projects/280dd2a0-d23d-4a71-91e1-dce4353163be/如何修改-charles-以解密模拟器-https
|
||
stable_id: 120e75c2-feea-450c-b525-5623768b318f
|
||
scope: project
|
||
memory_type: experience
|
||
project_id: 280dd2a0-d23d-4a71-91e1-dce4353163be
|
||
usage_profile_id: 0c9feb46-d06e-43cd-9ef0-c5813c84a998
|
||
status: active
|
||
revision: 1
|
||
request_id: rapdrama-exp-charles-20260925-0346
|
||
created_at: '2026-09-24T19:48:51.330293+00:00'
|
||
updated_at: '2026-09-24T19:48:51.330293+00:00'
|
||
tags:
|
||
- charles
|
||
- ssl
|
||
- 配置
|
||
---
|
||
|
||
Charles 配置文件是 %APPDATA%\\Charles\\charles.config。根证书在 %APPDATA%\\Charles\\data\\ca\\charles-proxy-ssl-proxying-certificate.pem。修改前先备份该文件(本次备份名 charles.config.bak-capture),并先结束 Charles 进程再写。Charles 运行中写入会在退出时被覆盖。未知 XML 字段会让 Charles 整份配置回退到默认值,连注册信息一起丢掉;曾因为写入不存在的 enableSOCKSTransparentHTTPProxying 发生过一次,已用备份恢复。启动后要确认 registrationConfiguration 还在、端口 8888 在监听。
|
||
|
||
已验证可以写入并被 Charles 5.2.1 保留的 proxyConfiguration:
|
||
|
||
- port 8888
|
||
- enableSOCKSProxy false
|
||
- decryptSSL true
|
||
- transparentProxy true(后来为透明代理尝试打开;强制转发已撤销,这个开关仍留在配置里)
|
||
- sslLocations → locationPatterns → locationMatch:location 的 host 为 *、port 为 *,enabled 为 true
|
||
- windowsConfiguration:useHTTP false、useSOCKS false、enableAtStartup false
|
||
|
||
证书哈希用 Git 自带的 openssl 计算,不要用别的 adb:
|
||
|
||
C:\\Program Files\\Git\\usr\\bin\\openssl.exe x509 -inform PEM -subject_hash_old -in 证书.pem -noout
|
||
|
||
当前这张根证书的 subject_hash_old 是 275d036d。把 PEM 复制为 275d036d.0。重置 Charles 根证书后哈希会变,需要重新计算并重装。不要把私钥或注册码写进记忆。
|
||
|
||
验证:用该 openssl 经代理连 example.com:443,-CAfile 指向这张 PEM,Verification 为 OK。电脑直连不到的主机(如 android.googleapis.com)会在 Charles 里显示 CONNECT 超时和 503,这不是证书失败。当时机器上有 Clash Verge 服务,但没有本地代理端口在监听,Charles 是直连出去的。 |