Checkpoint Lab — Recording Web Traffic, HTTP(S) Test Script Recorder, and Certificate Setup
The checkpoint proves that recording can be used without leaving a dangerous trust footprint or a replay script full of captured state. The final artifact must be smaller than the browser session, use two explicit business transactions, correlate fresh dynamic values, and run in CLI mode after the recorder/proxy/browser trust have been removed.
Learning objectives
- Record one local synthetic HTTPS journey through JMeter with disposable profile-local CA trust.
- Keep only business requests and preserve an immutable raw capture.
- Refactor into Start Flow and Complete Flow transactions with Cookie Manager and dynamic correlation.
- Prove the cleaned JMX contains no captured literal flow/session values or external target hosts.
- Run the cleaned plan directly in non-GUI mode with bounded load.
- Remove recorder CA trust/profile/proxy state and document cleanup.
1. Exact assumptions and hard ceilings
| Item | Checkpoint baseline |
|---|---|
| JMeter | Apache JMeter 5.6.3. |
| Java | Java 17 JDK; JMeter 5.6.3 requires Java 8+, HTTPS recorder workflow requires keytool. |
| Plugins | None. |
| Browser | Disposable Firefox profile only; no sync/extensions/normal credentials. |
| Recorder | 127.0.0.1:8888 only. |
| Authorized target | https://localhost:8443 only for checkpoint capture/replay. |
| Target TLS |
Short-lived self-signed localhost fixture certificate in
fixture.p12.
|
| Recorder trust | JMeter temporary root CA imported only into disposable Firefox profile, then removed/profile deleted. |
| Clean replay load | 1 thread × 3 loops maximum. |
| Transactions | Exactly two business transactions: Start Flow and Complete Flow. |
| Secrets/data |
Synthetic student@example.invalid; no real
credentials/PII.
|
2. Setup and authorization/preflight
-
Create the 2-day localhost PKCS#12 fixture keystore with the
Lesson 2
keytoolcommand. - Compile/start
RecorderFixture. -
Verify
http://localhost:8080/healthand local HTTPS health using a loopback-only diagnostic client. - Record tool versions: JMeter 5.6.3, Java/Javac/Keytool version, Firefox version.
- Confirm JMeter recorder port 8888 is not externally exposed/listening before Start.
3. Write predictions before touching browser trust
Prediction A — unfiltered browser traffic: a raw Begin page will create at least the business Begin/Finish requests plus synthetic CSS, JS, and image resource requests.
Prediction B — filtered HTTPS recording: strict host Include + static-extension Exclude stores only Begin and Finish business calls even though excluded assets still pass through the proxy.
Prediction C — clean replay: each loop gets a fresh
FLOW_ID/CSRF_TOKEN and secure session
cookie; three loops produce three accepted Finish events with no
correlation failures.
Prediction D — trust cleanup: after deleting the disposable profile/removing its CA, no normal browser trust store was changed and the cleaned CLI JMX still runs because recorder CA trust is not required for replay.
4. Create and isolate the browser profile
Start a fresh Firefox profile directory, close normal Firefox windows, and verify its cookie/login state is empty. Configure proxy only after the recorder tree and strict target filters are prepared.
Record the profile directory path in the evidence packet so deletion can be independently verified.
5. Configure the recorder
| Recorder field | Checkpoint value |
|---|---|
| Port | 8888 |
| Target Controller | Dedicated Recording Controller / raw-capture branch |
| Include | localhost:8443/.* |
| Exclude | .*\.(?i:css|js|png|gif|svg|ico)(\?.*)? |
| Retrieve all embedded resources on generated samplers | Off for this business-call plan |
| Grouping | Optional for capture readability; final transactions are rebuilt deliberately. |
Start Recorder and wait for certificate generation/dialog.
6. Certificate proof before import
Use keytool -printcert on the exact generated
ApacheJMeterTemporaryRootCA.crt. Record:
- subject/issuer text;
- validity window;
- fingerprint;
- file path;
- that it is not currently trusted by the normal browser profile/OS for this lab.
Import only that CA into the disposable Firefox profile Authorities list.
7. Capture one HTTPS journey
- Set Firefox HTTP/HTTPS proxy to 127.0.0.1:8888 and clear localhost bypass.
- Navigate to
https://localhost:8443/begin. - Submit the synthetic form once.
- Stop Recorder immediately.
- Save raw capture as
raw-checkpoint.jmx. - Do not replay raw capture.
Inspect target events: Begin and Finish occurred. Inspect raw JMX: only the two business request samplers should be stored because the static extensions were excluded.
8. Remove recorder path/trust before plan cleanup
- Stop Recorder.
- Restore Firefox proxy settings.
- Remove the recorder CA from the disposable profile or delete the entire profile.
- Verify the profile path is gone if deletion is your rollback method.
- Keep the raw JMX and JMeter-generated certificate files only in the controlled lab workspace long enough for evidence review; never treat the CA/private-key material as a reusable organizational CA.
9. Build exactly two cleaned business transactions
Test Plan
├── HTTP Request Defaults
│ https://localhost:8443
├── HTTP Cookie Manager
└── Thread Group — 1 user × 3 loops
├── Transaction Controller — Start Flow
│ └── Begin — GET /begin
│ ├── CSS Selector Extractor FLOW_ID
│ │ selector: input[name=flow_id]
│ │ attribute: value
│ └── CSS Selector Extractor CSRF_TOKEN
│ selector: input[name=csrf]
│ attribute: value
└── Transaction Controller — Complete Flow
└── Finish — POST /finish
flow_id=${FLOW_ID}
csrf=${CSRF_TOKEN}
email=student@example.invalid
Add assertions for required extracted variables, Begin HTTP 200, Finish HTTP 200, and accepted body marker. Remove unnecessary recorded browser headers and all literal captured dynamic values.
10. Preserve cleanup diff and secret scan
git diff --no-index -- raw-checkpoint.jmx cleaned-checkpoint.jmx > evidence/recording-cleanup.diff
python tools/scan_jmx.py raw-checkpoint.jmx
python tools/scan_jmx.py cleaned-checkpoint.jmx --clean
The raw inventory is expected to show literal captured flow/csrf values. The clean scan must not. If the clean scan hits a suspicious pattern, investigate; do not weaken the scanner just to make the checkpoint green.
11. Run clean plan without recorder/browser proxy
jmeter.bat -n `
-t cleaned-checkpoint.jmx `
-l results\checkpoint-clean.jtl `
-j results\checkpoint-clean-jmeter.log
The Recorder remains stopped. Firefox is not needed. No recorder CA trust is needed. The plan connects directly to the synthetic HTTPS target.
12. Expected clean-run evidence
For 1 thread × 3 loops:
| Evidence | Expected |
|---|---|
| Begin target events | 3 |
| Finish target events | 3 |
| Finish status | All accepted/HTTP 200 |
| Correlation failures | 0 |
| Explicit replay of CSS/JS/GIF | 0 |
| Literal FLOW/CSRF/session values in cleaned JMX | 0 |
| External hosts in cleaned JMX | 0 |
Transaction Controller rows may add reporting samples to JTL depending on its parent/additional settings, but target request count remains six business HTTP requests.
13. Verify predictions independently
- Use target event log rather than JTL alone to count real Begin/Finish requests.
- Use raw-versus-clean diff to prove static/browser-specific material was removed.
- Use cleaned JMX scan + manual review to prove no literal captured session values remain.
- Use Firefox certificate/profile inspection or profile-directory deletion to prove recorder trust rollback.
-
Use JTL + matching
jmeter.log+ generator observation to prove the clean plan executed directly.
14. Required evidence packet
| Artifact | Required content |
|---|---|
| Recorder configuration | Port, target controller, include/exclude, grouping/resource settings. |
| Scoped CA/trust note | CA path/fingerprint/validity + disposable Firefox profile path + proof of removal. |
| Filtered request list | Raw stored business samplers and target event list showing excluded resources passed separately. |
| Raw JMX | Immutable/checksummed authoring draft; not used for load. |
| Cleaned JMX diff | Defaults, Cookie Manager, transactions, correlation, removed literals/noise. |
| Correlation evidence | Fresh FLOW/CSRF/session per iteration; accepted Finish target events. |
| Secret/host scan | Raw inventory + cleaned-plan PASS and manual review. |
JTL + jmeter.log |
Bounded direct CLI replay evidence. |
| Certificate cleanup checklist | Recorder stopped, proxy restored, profile CA removed/profile deleted. |
| Validity statement | Recorder discovery timing/assets are not the production workload model. |
15. Final verification checklist
- Only localhost fixture traffic was recorded.
- Recorder bound to loopback and stopped after one journey.
- Recorder CA trust existed only in disposable Firefox profile.
- No normal/system trust store was modified.
- Raw JMX was preserved but never load-tested.
- Clean plan has exactly two business transactions.
- Cookie state is managed by HTTP Cookie Manager.
- Dynamic values are extracted from each Begin response.
- Cleaned JMX contains no literal captured FLOW/CSRF/session values or external hosts.
- CLI replay remains ≤1 thread × 3 loops and produces zero correlation failures.
16. Validity statement
17. Cleanup / rollback
- Stop JMeter Recorder and local fixture.
- Restore/remove disposable Firefox proxy settings.
- Remove recorder CA from profile or delete the profile directory.
-
Delete disposable fixture
fixture.p12after evidence review if no longer needed. - If using a dedicated lab JMeter copy/launch directory, delete its recorder keystore/temporary CA artifacts after evidence review; do not indiscriminately delete shared installation files used by other tests.
- Retain only sanitized/raw evidence according to your local policy; never commit real secrets/PII.
18. What Chapter 13 adds to the operating model
The performance-testing operating model now has a recording/trust contract: authorized host scope, disposable browser/profile, recorder proxy binding, CA fingerprint/trust location/expiry, include/exclude policy, raw-capture provenance, secret scan, refactoring diff, correlation proof, and certificate/proxy rollback are reviewable before the plan becomes load-test code.
Chapter 14 moves to REST and JSON API Performance Testing. The clean-plan discipline from this chapter is directly useful there: APIs are often best built manually from contracts, while recorder-derived HTTP calls should already be reduced to explicit endpoints, parameters, headers, assertions, correlation, and workload semantics before REST-specific analysis begins.
Knowledge check
What is the strongest proof that recorder trust cleanup succeeded?
The temporary CA is absent from the disposable profile/trust location or the entire disposable profile directory is deleted, while normal/system trust was never modified.
Why is the raw recording preserved even though it is not replayed?
It is discovery evidence that makes filtering, parameterization, correlation, and secret removal reviewable as a diff.
What should happen if the cleaned JMX scan still finds FLOW-00001?
Stop and investigate the remaining literal captured state; do not weaken the scanner or proceed to load.
Why can the cleaned CLI plan work after recorder CA trust is removed?
Recorder CA trust is only needed for browser→recorder HTTPS interception during authoring; replay connects directly as JMeter HTTP requests.
Why is Chapter 14 a natural next step?
Once browser capture is reduced to explicit clean HTTP calls, REST/JSON-specific request design, payloads, headers, assertions, and API workload modeling can be taught directly.
Official references and version notes
- Component Reference — HTTP(S) Test Script Recorder — proxy, filtering, recording controller, certificate generation, CA trust, cookies, redirects, and UDV replacement.
- HTTP(S) Test Script Recorder tutorial — current recording-template workflow and browser proxy setup.
- Getting Started — Java/JDK requirement, keytool note for HTTPS recording, GUI/CLI conventions, and JMeter HTTP certificate behavior.
- Properties Reference — recorder and certificate properties such as proxy.cert.validity, proxy.ssl.protocol, proxy.pause, and redirect handling.
- Best Practices — using the recorder for rough drafts, variable replacement, and checking proxy routing.
- Apache JMeter downloads — current stable release and Java requirement.
Version-sensitive statements were rechecked against current Apache
JMeter primary documentation on 2026-09-05. The course baseline
remains Apache JMeter 5.6.3 with a Java 17 JDK
and no third-party JMeter plugins; JMeter 5.6.3 requires Java 8+.
A JDK is preferred here because HTTPS recording needs the
keytool utility. HTTP(S) Test Script Recorder is a
local HTTP/HTTPS proxy, default port 8888.
Include/Exclude patterns are regular expressions evaluated against
the full host/port/path/query string; requests still pass through
the proxy even when a filter prevents them from being stored. With
Java 8+ dynamic certificate mode, JMeter generates per-host
certificates signed by its temporary root CA; the default recorder
certificate validity is 7 days via
proxy.cert.validity. The exported
ApacheJMeterTemporaryRootCA.crt is created when
recorder certificates are generated and must be removed from
browser trust after use. Anyone who can access the recorder
keystore/private-key material while a browser trusts that CA has a
powerful interception capability, so the mandatory lab imports it
only into a disposable Firefox profile. During recording, the
browser manages cookies; the cleaned JMeter replay plan needs an
HTTP Cookie Manager. JMeter's HTTP samplers accept server
certificates broadly for test flexibility, so the synthetic
localhost target can use its own short-lived self-signed fixture
certificate without importing that target certificate into the
browser or OS trust store.
Keep the academy open
Support free, practical DevOps education.
Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0
Send only Ethereum/ERC-20 compatible assets to this
address.