Contact Support


Configuring Client Certificate Authentication

Netsparker supports the Client Certificate Authentication mechanism, enabling you to configure scans for websites that require Client Certificate authentication.

It is not possible to configure both Client Certificate Authentication and Smart Card Authentication at the same time.

For further information, see Configuring Smart Card Authentication in Netsparker Standard.

Ensure that the selected certificate is NOT imported with strong key protection.

Client Certificate Fields

This table lists and describes the fields in the Authentication Client Certificate section.



Client Certificate

Select to enable a client certificate to be used to log in to the web application.


Click to browse and upload the certificate file.


Enter the password for the certificate.

How to Configure Client Certificate Authentication in Netsparker Enterprise
  1. Log in to Netsparker Enterprise.
  2. From the main menu, click Scans, then New Scan. The New Scan window is displayed.
  3. From the Authentication tab, select Client Certificate. The Client Certificate section is displayed.
  4. Select the Enabled checkbox.

5. Click Browse to upload the certificate

6. Select a file, then click Open.

In Netsparker Enterprise, client certificate files can only be added in the following formats: cer, crt, der, pem, pfx, p7b, p7r, p12, spc.

7. Click Start Scan.

How to Configure Client Certificate Authentication in Netsparker Standard
  1. Open Netsparker Standard.
  2. From the Home tab, click New. The Start a New Website or Web Service Scan dialog is displayed.

3. Click the Client Certificate tab. The Client Certificate Authentication section is displayed.

4. In the Client Certificate Authentication section, check Enabled.

5. From the dropdown, select the required certificate.

6. Alternatively, click Add New to add a new client certificate. The Certificate to Install dialog is displayed.

7. Select file.

  • Click on file.

  • Click Open
Client certificate files can only be added in PFX (Personal Information Exchange) or Cert (Digital Certificate) formats.

8. Click Start Scan.


Highly accurate, fast & easy-to-use Web Application Security Scanner

Get a demo