Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. DevSecOps
  3. Bad SSL

Bad SSL

Apache-2.0HTML

A collection of test subdomains with intentionally broken SSL configurations for testing client security behavior.

Visit WebsiteGitHubGitHub
3.0k stars204 forks0 contributors

What is Bad SSL?

badssl.com is a testing website that provides numerous subdomains with intentionally broken SSL/TLS configurations. It allows developers to test how web clients, browsers, and applications respond to various SSL certificate errors and security warnings. The project serves as a practical tool for validating client-side security behavior.

Target Audience

Web developers, security engineers, QA testers, and browser developers who need to test how their applications handle SSL/TLS certificate errors and security warnings.

Value Proposition

Developers choose badssl.com because it provides a comprehensive, ready-to-use collection of real SSL misconfigurations in one place, eliminating the need to manually create test certificates. It's maintained by security professionals from major browser teams and offers reliable test cases for common SSL issues.

Overview

:lock: Memorable site for testing clients against bad SSL configs.

Use Cases

Best For

  • Testing browser behavior with expired SSL certificates
  • Validating client applications' handling of self-signed certificates
  • Testing mixed content security warnings in web applications
  • Verifying HSTS implementation in browsers and clients
  • Testing SSL certificate validation in mobile apps
  • Educational demonstrations of SSL/TLS security concepts

Not Ideal For

  • Automated CI/CD pipelines requiring stable, documented test endpoints
  • Production environments needing guaranteed uptime or SLAs for security testing
  • Teams seeking comprehensive cryptographic analysis beyond common misconfigurations
  • Educational courses that require theoretical explanations alongside practical examples

Pros & Cons

Pros

Comprehensive Test Coverage

Offers a wide range of subdomains for expired, self-signed, mixed content, weak ciphers, HSTS, and more, as listed on badssl.com, providing real-world SSL misconfigurations in one place.

Expert Maintenance

Co-maintained by security professionals from Mozilla Firefox and Google Chrome, ensuring relevance and accuracy for browser-specific testing needs.

Free and Accessible

Hosted on Google Cloud with no cost to users, making it readily available for manual testing without setup overhead for basic use.

Hands-On Local Setup

Includes Docker-based instructions in the README for local development, allowing developers to replicate test environments by editing hosts files and adding certificates.

Cons

No Stability Guarantees

The disclaimer states that subdomains could change without notice, making it unreliable for automated testing or long-term integration due to potential breaking changes.

Manual Testing Focus

Designed primarily for manual UI testing, as per the README, lacking APIs or support for automated scripts, which limits use in continuous testing workflows.

Complex Local Configuration

Setting up locally requires editing system hosts files and manually adding root certificates, which can be error-prone and time-consuming compared to simpler testing tools.

Frequently Asked Questions

Quick Stats

Stars3,032
Forks204
Contributors0
Open Issues192
Last commit1 month ago
CreatedSince 2015

Tags

#certificate-validation#web-security#chrome#tls#browser-testing#python#testing#nginx#ssl#security-education#rcpp#https#tls-testing#security-testing#browser#sha1

Built With

D
Docker

Links & Resources

Website

Included in

DevSecOps1.7k
Auto-fetched 3 hours ago

Related Projects

Kubernetes GoatKubernetes Goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

Stars5,725
Forks1,033
Last commit3 months ago
cicd-goatcicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Stars2,279
Forks414
Last commit2 years ago
WrongSecretsWrongSecrets

Vulnerable app with examples showing how to not use secrets

Stars1,451
Forks591
Last commit4 days ago
TerragoatTerragoat

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

Stars1,302
Forks5,819
Last commit1 year ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub