Chapter 13Lesson 05~240 minutes

Checkpoint Lab — Recording Web Traffic, HTTP(S) Test Script Recorder, and Certificate Setup

The checkpoint proves that recording can be used without leaving a dangerous trust footprint or a replay script full of captured state. The final artifact must be smaller than the browser session, use two explicit business transactions, correlate fresh dynamic values, and run in CLI mode after the recorder/proxy/browser trust have been removed.

CheckpointHTTPS recordingTwo transactionsSecret scanCertificate cleanup

Learning objectives

  • Record one local synthetic HTTPS journey through JMeter with disposable profile-local CA trust.
  • Keep only business requests and preserve an immutable raw capture.
  • Refactor into Start Flow and Complete Flow transactions with Cookie Manager and dynamic correlation.
  • Prove the cleaned JMX contains no captured literal flow/session values or external target hosts.
  • Run the cleaned plan directly in non-GUI mode with bounded load.
  • Remove recorder CA trust/profile/proxy state and document cleanup.

1. Exact assumptions and hard ceilings

Item Checkpoint baseline
JMeter Apache JMeter 5.6.3.
Java Java 17 JDK; JMeter 5.6.3 requires Java 8+, HTTPS recorder workflow requires keytool.
Plugins None.
Browser Disposable Firefox profile only; no sync/extensions/normal credentials.
Recorder 127.0.0.1:8888 only.
Authorized target https://localhost:8443 only for checkpoint capture/replay.
Target TLS Short-lived self-signed localhost fixture certificate in fixture.p12.
Recorder trust JMeter temporary root CA imported only into disposable Firefox profile, then removed/profile deleted.
Clean replay load 1 thread × 3 loops maximum.
Transactions Exactly two business transactions: Start Flow and Complete Flow.
Secrets/data Synthetic student@example.invalid; no real credentials/PII.
Abort: any non-local host in raw recording, any real credential/PII, recorder proxy exposed beyond loopback, recorder CA imported into a system/normal-profile trust store, unexpected runaway traffic, or replay above 1 thread × 3 loops.

2. Setup and authorization/preflight

  1. Create the 2-day localhost PKCS#12 fixture keystore with the Lesson 2 keytool command.
  2. Compile/start RecorderFixture.
  3. Verify http://localhost:8080/health and local HTTPS health using a loopback-only diagnostic client.
  4. Record tool versions: JMeter 5.6.3, Java/Javac/Keytool version, Firefox version.
  5. Confirm JMeter recorder port 8888 is not externally exposed/listening before Start.

3. Write predictions before touching browser trust

Prediction A — unfiltered browser traffic: a raw Begin page will create at least the business Begin/Finish requests plus synthetic CSS, JS, and image resource requests.

Prediction B — filtered HTTPS recording: strict host Include + static-extension Exclude stores only Begin and Finish business calls even though excluded assets still pass through the proxy.

Prediction C — clean replay: each loop gets a fresh FLOW_ID/CSRF_TOKEN and secure session cookie; three loops produce three accepted Finish events with no correlation failures.

Prediction D — trust cleanup: after deleting the disposable profile/removing its CA, no normal browser trust store was changed and the cleaned CLI JMX still runs because recorder CA trust is not required for replay.

4. Create and isolate the browser profile

Start a fresh Firefox profile directory, close normal Firefox windows, and verify its cookie/login state is empty. Configure proxy only after the recorder tree and strict target filters are prepared.

Record the profile directory path in the evidence packet so deletion can be independently verified.

5. Configure the recorder

Recorder field Checkpoint value
Port 8888
Target Controller Dedicated Recording Controller / raw-capture branch
Include localhost:8443/.*
Exclude .*\.(?i:css|js|png|gif|svg|ico)(\?.*)?
Retrieve all embedded resources on generated samplers Off for this business-call plan
Grouping Optional for capture readability; final transactions are rebuilt deliberately.

Start Recorder and wait for certificate generation/dialog.

6. Certificate proof before import

Use keytool -printcert on the exact generated ApacheJMeterTemporaryRootCA.crt. Record:

  • subject/issuer text;
  • validity window;
  • fingerprint;
  • file path;
  • that it is not currently trusted by the normal browser profile/OS for this lab.

Import only that CA into the disposable Firefox profile Authorities list.

7. Capture one HTTPS journey

  1. Set Firefox HTTP/HTTPS proxy to 127.0.0.1:8888 and clear localhost bypass.
  2. Navigate to https://localhost:8443/begin.
  3. Submit the synthetic form once.
  4. Stop Recorder immediately.
  5. Save raw capture as raw-checkpoint.jmx.
  6. Do not replay raw capture.

Inspect target events: Begin and Finish occurred. Inspect raw JMX: only the two business request samplers should be stored because the static extensions were excluded.

8. Remove recorder path/trust before plan cleanup

  1. Stop Recorder.
  2. Restore Firefox proxy settings.
  3. Remove the recorder CA from the disposable profile or delete the entire profile.
  4. Verify the profile path is gone if deletion is your rollback method.
  5. Keep the raw JMX and JMeter-generated certificate files only in the controlled lab workspace long enough for evidence review; never treat the CA/private-key material as a reusable organizational CA.

9. Build exactly two cleaned business transactions

Test Plan
├── HTTP Request Defaults
│   https://localhost:8443
├── HTTP Cookie Manager
└── Thread Group — 1 user × 3 loops
    ├── Transaction Controller — Start Flow
    │   └── Begin — GET /begin
    │       ├── CSS Selector Extractor FLOW_ID
    │       │   selector: input[name=flow_id]
    │       │   attribute: value
    │       └── CSS Selector Extractor CSRF_TOKEN
    │           selector: input[name=csrf]
    │           attribute: value
    └── Transaction Controller — Complete Flow
        └── Finish — POST /finish
            flow_id=${FLOW_ID}
            csrf=${CSRF_TOKEN}
            email=student@example.invalid

Add assertions for required extracted variables, Begin HTTP 200, Finish HTTP 200, and accepted body marker. Remove unnecessary recorded browser headers and all literal captured dynamic values.

10. Preserve cleanup diff and secret scan

git diff --no-index -- raw-checkpoint.jmx cleaned-checkpoint.jmx > evidence/recording-cleanup.diff

python tools/scan_jmx.py raw-checkpoint.jmx
python tools/scan_jmx.py cleaned-checkpoint.jmx --clean

The raw inventory is expected to show literal captured flow/csrf values. The clean scan must not. If the clean scan hits a suspicious pattern, investigate; do not weaken the scanner just to make the checkpoint green.

11. Run clean plan without recorder/browser proxy

jmeter.bat -n `
  -t cleaned-checkpoint.jmx `
  -l results\checkpoint-clean.jtl `
  -j results\checkpoint-clean-jmeter.log

The Recorder remains stopped. Firefox is not needed. No recorder CA trust is needed. The plan connects directly to the synthetic HTTPS target.

12. Expected clean-run evidence

For 1 thread × 3 loops:

Evidence Expected
Begin target events 3
Finish target events 3
Finish status All accepted/HTTP 200
Correlation failures 0
Explicit replay of CSS/JS/GIF 0
Literal FLOW/CSRF/session values in cleaned JMX 0
External hosts in cleaned JMX 0

Transaction Controller rows may add reporting samples to JTL depending on its parent/additional settings, but target request count remains six business HTTP requests.

13. Verify predictions independently

  • Use target event log rather than JTL alone to count real Begin/Finish requests.
  • Use raw-versus-clean diff to prove static/browser-specific material was removed.
  • Use cleaned JMX scan + manual review to prove no literal captured session values remain.
  • Use Firefox certificate/profile inspection or profile-directory deletion to prove recorder trust rollback.
  • Use JTL + matching jmeter.log + generator observation to prove the clean plan executed directly.

14. Required evidence packet

Artifact Required content
Recorder configuration Port, target controller, include/exclude, grouping/resource settings.
Scoped CA/trust note CA path/fingerprint/validity + disposable Firefox profile path + proof of removal.
Filtered request list Raw stored business samplers and target event list showing excluded resources passed separately.
Raw JMX Immutable/checksummed authoring draft; not used for load.
Cleaned JMX diff Defaults, Cookie Manager, transactions, correlation, removed literals/noise.
Correlation evidence Fresh FLOW/CSRF/session per iteration; accepted Finish target events.
Secret/host scan Raw inventory + cleaned-plan PASS and manual review.
JTL + jmeter.log Bounded direct CLI replay evidence.
Certificate cleanup checklist Recorder stopped, proxy restored, profile CA removed/profile deleted.
Validity statement Recorder discovery timing/assets are not the production workload model.

15. Final verification checklist

  • Only localhost fixture traffic was recorded.
  • Recorder bound to loopback and stopped after one journey.
  • Recorder CA trust existed only in disposable Firefox profile.
  • No normal/system trust store was modified.
  • Raw JMX was preserved but never load-tested.
  • Clean plan has exactly two business transactions.
  • Cookie state is managed by HTTP Cookie Manager.
  • Dynamic values are extracted from each Begin response.
  • Cleaned JMX contains no literal captured FLOW/CSRF/session values or external hosts.
  • CLI replay remains ≤1 thread × 3 loops and produces zero correlation failures.

16. Validity statement

Example: “Using Apache JMeter 5.6.3 and a Java 17 JDK, one synthetic HTTPS journey on localhost:8443 was captured through the loopback HTTP(S) Test Script Recorder on port 8888 using a disposable Firefox profile. JMeter's temporary recording CA was fingerprint-checked, trusted only by that profile, then removed with the profile/proxy after capture. Strict host and static-extension filters stored only Begin/Finish business calls. The immutable raw recording contained captured dynamic form values; a cleaned copy centralized HTTPS defaults, added HTTP Cookie Manager, extracted fresh flow/csrf values, and grouped the two calls into Start Flow/Complete Flow transactions. Secret/host scanning and manual review found no literal captured session values or external hosts in the cleaned JMX. A direct 1-thread × 3-loop CLI replay, with Recorder/browser trust absent, produced three accepted Finish events. This validates recorder isolation and plan refactoring—not production capacity, browser rendering performance, or authorization to record non-lab systems.”

17. Cleanup / rollback

  1. Stop JMeter Recorder and local fixture.
  2. Restore/remove disposable Firefox proxy settings.
  3. Remove recorder CA from profile or delete the profile directory.
  4. Delete disposable fixture fixture.p12 after evidence review if no longer needed.
  5. If using a dedicated lab JMeter copy/launch directory, delete its recorder keystore/temporary CA artifacts after evidence review; do not indiscriminately delete shared installation files used by other tests.
  6. Retain only sanitized/raw evidence according to your local policy; never commit real secrets/PII.

18. What Chapter 13 adds to the operating model

The performance-testing operating model now has a recording/trust contract: authorized host scope, disposable browser/profile, recorder proxy binding, CA fingerprint/trust location/expiry, include/exclude policy, raw-capture provenance, secret scan, refactoring diff, correlation proof, and certificate/proxy rollback are reviewable before the plan becomes load-test code.

Chapter 14 moves to REST and JSON API Performance Testing. The clean-plan discipline from this chapter is directly useful there: APIs are often best built manually from contracts, while recorder-derived HTTP calls should already be reduced to explicit endpoints, parameters, headers, assertions, correlation, and workload semantics before REST-specific analysis begins.

Knowledge check

What is the strongest proof that recorder trust cleanup succeeded?

Why is the raw recording preserved even though it is not replayed?

What should happen if the cleaned JMX scan still finds FLOW-00001?

Why can the cleaned CLI plan work after recorder CA trust is removed?

Why is Chapter 14 a natural next step?

Next chapter

REST and JSON API Performance Testing

Chapter 14 focuses on request/response contracts, JSON payloads, headers/status semantics, API correlation, idempotency, and realistic REST workload design.

Official references and version notes

Version and compatibility note

Version-sensitive statements were rechecked against current Apache JMeter primary documentation on 2026-09-05. The course baseline remains Apache JMeter 5.6.3 with a Java 17 JDK and no third-party JMeter plugins; JMeter 5.6.3 requires Java 8+. A JDK is preferred here because HTTPS recording needs the keytool utility. HTTP(S) Test Script Recorder is a local HTTP/HTTPS proxy, default port 8888. Include/Exclude patterns are regular expressions evaluated against the full host/port/path/query string; requests still pass through the proxy even when a filter prevents them from being stored. With Java 8+ dynamic certificate mode, JMeter generates per-host certificates signed by its temporary root CA; the default recorder certificate validity is 7 days via proxy.cert.validity. The exported ApacheJMeterTemporaryRootCA.crt is created when recorder certificates are generated and must be removed from browser trust after use. Anyone who can access the recorder keystore/private-key material while a browser trusts that CA has a powerful interception capability, so the mandatory lab imports it only into a disposable Firefox profile. During recording, the browser manages cookies; the cleaned JMeter replay plan needs an HTTP Cookie Manager. JMeter's HTTP samplers accept server certificates broadly for test flexibility, so the synthetic localhost target can use its own short-lived self-signed fixture certificate without importing that target certificate into the browser or OS trust store.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0 Send only Ethereum/ERC-20 compatible assets to this address.