Hero Background

Power Your Software Testing with AI Agents and Cloud

The Native AI-Agentic Cloud Platform to Supercharge Quality Engineering. Test Intelligently and Ship Faster.

HyperExecute

How to Install Custom Certificates in HyperExecute Tests

Install custom SSL and client certificates in HyperExecute test runs with YAML pre steps or pre-run scripts, plus a tested client certificate example.

Last Updated on:

Custom certificate installation lets a test suite trust the same SSL or TLS certificate a production server uses, without a DevOps engineer manually configuring each machine.

A YAML pre-command uploads and installs the certificate before the run starts, so the suite authenticates against an internal or self-signed certificate automatically.

This guide covers securing a customized test environment, installing certificates through YAML, the resulting benefits, and how AI agents fit into certificate-based testing now.

TL;DR

  • Custom Certificate Installation on HyperExecute uploads a certificate through a YAML pre-command, so a test suite authenticates before the run begins.
  • A test suite failing on a self-signed or internal certificate is a common cause of blocked test runs in secured environments.
  • A client certificate cannot be bypassed by ignoring certificate errors: in a cloud test, the server returned HTTP 400 until the certificate was presented, then HTTP 200.
  • In HyperExecute, a YAML pre step runs cert_manager.exe to install a .pfx certificate for Chrome before the tests start.
  • AI agents can flag an expiring certificate in a continuous testing pipeline before it causes a test failure.
  • A security incident becomes harder to trace when a certificate is swapped automatically without an audit log.

Why Do Tests Fail on Custom Certificates?

Browsers trust a site only when its TLS certificate chains to a certificate authority they already trust. Staging and internal apps often use a self-signed certificate or a private company CA, so a fresh test machine rejects them and the test fails before the first step runs.

Some apps also require mutual TLS, where the browser must present its own client certificate, usually a .pfx or .p12 file. That is a separate problem: the server refuses the request unless the certificate is installed, and telling the browser to ignore certificate errors does not help.

A client certificate test on the cloud - On September 30, 2026, I ran Playwright against client.badssl.com, a public test host that requires a client certificate, in Chrome 154 on the TestMu AI cloud, three times each way:

Browser contextResult
No client certificateHTTP 400: "No required SSL certificate was sent", in every run
ignoreHTTPSErrors set, no certificate (client-cert-missing.badssl.com)HTTP 400, the same refusal
Client certificate presentedHTTP 200 in all 3 runs

The certificate file also needed one fix first. The published .p12 used a legacy encryption algorithm that current OpenSSL builds reject, so it had to be converted to PEM before the test could load it. Check old certificate bundles the same way before you add them to a pipeline.

Installing Certificates with HyperExecute

TestMu AI documents two ways to put a certificate on the test machine before your tests start.

Method 1: HyperExecute YAML Pre Step

HyperExecute runs every command in the pre list of the YAML file before test execution. For a Chrome client certificate, the HyperExecute C# use cases documentation runs the bundled cert_manager.exe tool with the certificate file:

pre:
  - "%HYPEREXECUTE_WORKING_DIR%//Hyperexecute//cert_manager.exe --chrome -i atest089.pfx"
  • --chrome installs the certificate for the Chrome browser.
  • -i tells the tool to install the file that follows.
  • atest089.pfx is the certificate file, which must be available in the project that HyperExecute uploads.

Method 2: Pre-Run Scripts on the Selenium Grid

For Selenium tests on the TestMu AI grid, the pre-run executables guide installs a certificate with a script that runs before the session and removes it afterward:

  • Upload the certificate file through the user files API.
  • Write an install script. On Windows it uses Import-Certificate into the Cert:\LocalMachine\Root store; on macOS it uses security add-trusted-cert with the System keychain.
  • Write a deletion script so the certificate does not stay on the machine after the run.
  • Upload both scripts, then ask TestMu AI support to approve them.
  • Reference the certificate in lambda:userFiles and the approved scripts in the prerun capability.
Import-Certificate -FilePath "C:\Users\ltuser\Downloads\{NAME-OF-THE-CERTIFICATE}" -CertStoreLocation 'Cert:\LocalMachine\Root' -Verbose

Benefits of Installing Certificates

  • Tests reach secured environments - staging sites with private CAs and apps that require client certificates can be tested without turning off certificate checks.
  • No per-machine setup - the certificate is installed by the pre step or pre-run script on every fresh cloud machine, so nobody configures machines by hand.
  • Checks stay meaningful - ignoring certificate errors hides real certificate problems, while installing the certificate keeps validation on for everything else.
  • Cleanup is built in - the deletion script removes the certificate after the run, which matters when the certificate grants access to internal systems.

How Do AI Agents Manage Certificates In Continuous Testing Pipelines?

AI-driven orchestration in continuous testing pipelines can flag a missing or expiring certificate before a run starts and trigger the install step automatically.

This matters most in security testing, where a test suite has to authenticate against the same certificates a production environment uses. A DevOps testing workflow that installs certificates by hand for every environment does not scale once a team runs suites across many browsers, devices, and regions.

AI agents already fit into that certificate workflow in three concrete ways:

  • Automated certificate refresh - an agent watches certificate expiry dates across the test infrastructure and re-uploads a renewed certificate before the next scheduled run.
  • Environment-aware routing - for geo-distributed real device testing with HyperExecute, an agent applies the correct regional certificate to each device pool automatically.
  • Config drift detection - an agent flags a YAML pre-command that references an outdated or expired certificate file before the pipeline fails deep into a test run.

These checks still need a human review step, because an agent that swaps a certificate without leaving an audit trail makes a future security incident much harder to trace.

Conclusion

If tests fail on a staging certificate or a client certificate, install the certificate on the test machine instead of turning off certificate checks. In HyperExecute, add the cert_manager.exe command to the YAML pre steps; on the Selenium grid, use approved pre-run scripts that install the certificate and remove it after the run. The HyperExecute YAML guide covers the pre and post steps.

Author

...

Aman Chopra

Blogs: 15

  • Twitter
  • Linkedin

Aman Chopra is a DevOps Engineer and Community Contributor with over 7 years of experience in cloud technologies, software development, and software testing. Currently working at TestMu AI, Aman specializes in optimizing Azure cloud infrastructure, enhancing API accessibility, and integrating cloud platforms like AWS and GCP. With expertise in Git, Docker, Kubernetes, and CI/CD practices, Aman has contributed to various open-source projects and authored guides on cloud computing, containers, and CI/CD. He holds a B.Tech in Computer Science.

Add to Google preferred sources

Summarise with AI

Copied to Clipboard!
...

3000+ Browsers. One Platform.

See exactly how your site performs everywhere.

Try it free
...

Write Tests in Plain English with KaneAI

Create, debug, and evolve tests using natural language.

Try for free

Custom Certificate Installation FAQs

Did you find this page helpful?

More Related Blogs

TestMu AI forEnterprise

Get access to solutions built on Enterprise
grade security, privacy, & compliance

  • Advanced access controls
  • Advanced data retention rules
  • Advanced Local Testing
  • Premium Support options
  • Early access to beta features
  • Private Slack Channel
  • Unlimited Manual Accessibility DevTools Tests