# Possible to bypass cert verification in Requests.jl or HTTP.jl?

**URL:** <https://discourse.julialang.org/t/possible-to-bypass-cert-verification-in-requests-jl-or-http-jl/5032>\
**Category:** General Usage\
**Created:** [July 24, 2017, 12:17am UTC](https://discourse.julialang.org/t/possible-to-bypass-cert-verification-in-requests-jl-or-http-jl/5032 "2017-07-24T00:17:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![josefsachs](https://avatars.discourse-cdn.com/v4/letter/j/f475e1/32.png) [@josefsachs](https://discourse.julialang.org/u/josefsachs)\
**Post date:** [July 24, 2017, 12:17am UTC](https://discourse.julialang.org/t/possible-to-bypass-cert-verification-in-requests-jl-or-http-jl/5032/1 "2017-07-24T00:17:11Z")

</div>

Is there a way that I can bypass cert verification in Requests.jl or HTTP.jl (i.e., as a client),  
similar to curl’s -k option?

```julia
       -k, --insecure
              (TLS) By default, every SSL connection curl makes is verified to be secure. This option allows curl
              to proceed and operate even for server connections otherwise considered insecure.

              The server connection is verified by making sure the server's certificate contains the right name
              and verifies successfully using the cert store.

              See this online resource for further details:
               https://curl.haxx.se/docs/sslcerts.html

              See also --proxy-insecure and --cacert.

```

---

<div class="post-metadata">

**Author:** ![quinnj](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/quinnj/32/11_2.png) [@quinnj](https://discourse.julialang.org/u/quinnj)\
**Post date:** [July 24, 2017, 1:05am UTC](https://discourse.julialang.org/t/possible-to-bypass-cert-verification-in-requests-jl-or-http-jl/5032/2 "2017-07-24T01:05:49Z")

</div>

It’s an MbedTLS.jl option, so should work with either Requests or HTTP. With HTTP.jl, you’d do something like

```julia
using HTTP, MbedTLS
client = HTTP.Client(tlsconfig=MbedTLS.SSLConfig(false))
HTTP.get(client, url; options...)

```

---

<div class="post-metadata">

**Author:** ![josefsachs](https://avatars.discourse-cdn.com/v4/letter/j/f475e1/32.png) [@josefsachs](https://discourse.julialang.org/u/josefsachs)\
**Post date:** [July 24, 2017, 10:22am UTC](https://discourse.julialang.org/t/possible-to-bypass-cert-verification-in-requests-jl-or-http-jl/5032/3 "2017-07-24T10:22:16Z")

</div>

Thanks.

My colleague Keith Mason pointed out the following for Requests.jl.  
[https://github.com/JuliaWeb/Requests.jl/issues/126](https://github.com/JuliaWeb/Requests.jl/issues/126)

---

<div class="post-metadata">

**Author:** ![malmaud](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/malmaud/32/29_2.png) [@malmaud](https://discourse.julialang.org/u/malmaud)\
**Post date:** [July 24, 2017, 6:47pm UTC](https://discourse.julialang.org/t/possible-to-bypass-cert-verification-in-requests-jl-or-http-jl/5032/4 "2017-07-24T18:47:58Z")

</div>

I introduced the MbedTLS integration to Requests, so it would logically fall to me to write that documentation. There isn’t much motivation though since HTTP is intended to replace Requests.
