Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Firefox’s insecure-connection page means certificate validation failed. First record the exact error code and determine whether one site or many sites are affected. For a controlled test target whose invalid certificate is expected, create the WebDriver session with acceptInsecureCerts set to true. That permits navigation for the entire session; it does not repair the certificate. For production-like testing, fix the server chain or install the correct trust anchor instead.
What the Firefox error means
Firefox checks a website certificate to verify the site and protect the encrypted connection. An insecure-connection warning therefore identifies a failed validation check, not automatically the cause. The warning page’s code is the most useful starting point.
Common codes
SEC_ERROR_UNKNOWN_ISSUER: Firefox cannot establish trust in the certificate issuer.MOZILLA_PKIX_ERROR_MITM_DETECTED: the certificate resembles one produced by an intercepting authority that Firefox does not trust.ERROR_SELF_SIGNED_CERT: the certificate is self-signed and is not trusted by the browser.
A failure on one hostname usually points to that server’s certificate, chain, or intermediate configuration. Failures on many unrelated HTTPS sites suggest a work-network proxy, antivirus TLS scanning, another interception device, or a machine-wide trust problem.
Free tools Windows power users keep installed
One-click scans. No signup required.
Diagnose before changing Selenium
- Run the navigation manually in the same Firefox installation and record the complete URL, warning text, and error code.
- Try two or three unrelated HTTPS sites. Keep the scope: one site and one certificate problem require a different fix from a browser that rejects nearly everything.
- For a single site, inspect the certificate’s subject, issuer, validity dates, and intermediate chain. A missing intermediate is a common server-side cause.
- For multiple sites, ask whether a corporate proxy or antivirus product deliberately intercepts TLS. Obtain the organization’s approved root certificate and trust procedure rather than accepting arbitrary certificates.
- Note Selenium, Firefox, geckodriver, and language-binding versions, and whether the browser runs locally or on a remote grid. Selenium’s Firefox documentation states that Selenium 4 requires Firefox 78 or newer and recommends the latest geckodriver; it does not provide one universal compatibility matrix for every release combination.
Use acceptInsecureCerts for a controlled test
acceptInsecureCerts is a standard WebDriver session capability. When false, an invalid certificate can make navigation return a certificate error. When true, the browser accepts invalid certificates for that newly created session. The setting is session-wide, so it is not a per-URL switch.
#1 Best Overall
Python with Selenium
Install Selenium in the environment that will launch Firefox, then create the option before constructing the driver:
from selenium import webdriver
from selenium.webdriver.firefox.options import Options
options = Options()
options.accept_insecure_certs = True
driver = webdriver.Firefox(options=options)
try:
driver.get("https://staging.example.test")
print(driver.title)
finally:
driver.quit()
The URL is an example; replace it with your controlled test host. Keep this configuration in a test-specific fixture or profile, not in a shared default used for security or certificate-regression tests.
Remote Python session
Pass the same options object when creating the remote session. The browser host, not your laptop, must have the required Firefox and geckodriver setup:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11from selenium import webdriver
from selenium.webdriver.firefox.options import Options
options = Options()
options.accept_insecure_certs = True
driver = webdriver.Remote(
command_executor="http://grid-host:4444/wd/hub",
options=options,
)
try:
driver.get("https://staging.example.test")
finally:
driver.quit()
A local Firefox profile or trust store is not automatically copied to a remote browser. Configure certificates on the machine that actually runs Firefox, or provide a profile through the grid’s supported capabilities.
JavaScript and Java capability shape
Client syntax varies by binding and release, but the capability being sent is the same. In JavaScript, set the Firefox option when building the driver:
const { Builder } = require('selenium-webdriver');
const firefox = require('selenium-webdriver/firefox');
const options = new firefox.Options();
options.setAcceptInsecureCerts(true);
(async () => {
const driver = await new Builder()
.forBrowser('firefox')
.setFirefoxOptions(options)
.build();
try {
await driver.get('https://staging.example.test');
} finally {
await driver.quit();
}
})();
For Java, Ruby, and other clients, use that binding’s current Firefox options API to send the standard acceptInsecureCerts: true capability. Verify the generated session capabilities in your grid logs if the setting appears to have no effect.
When accepting the certificate is the wrong fix
Repair a site you control
Install a certificate valid for the hostname, serve the complete intermediate chain, and ensure the system clock is correct. A browser bypass can hide a broken deployment that real users will reject. Keep at least one test path that validates certificates normally so a renewal or chain regression is detected.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Trust an intentional internal authority
In a controlled laboratory or corporate network, a proxy may intentionally re-sign traffic. Ask the network administrator for the approved interception root and install it in Firefox’s trust configuration or supply it through a managed profile. Do not import an unknown certificate merely to make a test pass.
Rank #3
Understand the security and fidelity trade-off
Session-wide acceptance allows navigation despite an invalid certificate, reducing protection during that run. It also means the test cannot detect certificate-chain failures that users would encounter. Use it only when certificate validation is outside the test’s purpose and the target is controlled.
Firefox cases where a bypass is unavailable
The manual “Accept the Risk and Continue” control can be absent for HSTS sites, certain critical certificate errors, or enterprise-managed Firefox installations that disable bypasses. This is expected behavior, not a Selenium defect. Identify the certificate condition and configure the intended trust relationship; do not attempt to automate around an HSTS policy by default.
Profiles, preferences, and certificates
Selenium’s Python Firefox options support preferences through set_preference, and Firefox options can carry a profile with custom certificates. Use these mechanisms only for a certificate authority your test environment is supposed to trust. The exact profile and certificate must be available on the remote browser host when execution is distributed.
from selenium import webdriver
from selenium.webdriver.firefox.options import Options
options = Options()
options.set_preference("network.trr.mode", 5) # example preference; use only when required
# Supply a managed profile or certificate using your grid's documented method.
driver = webdriver.Firefox(options=options)
try:
driver.get("https://internal.example.test")
finally:
driver.quit()
Do not copy this example preference into every suite without understanding its network effect. Certificate installation is environment-specific; coordinate with the administrator who owns the trust policy.
Rank #4
Troubleshooting checklist
The warning remains after setting the option
- Confirm the option was attached before
webdriver.Firefox(...)orwebdriver.Remote(...); changing it after session creation cannot alter that session’s capability. - Make sure the test is using the intended driver and browser, not a separately launched Firefox process.
- Inspect the new session’s capabilities in driver or grid logs and check that the remote node received
acceptInsecureCerts: true. - Reproduce with a fresh session; capabilities do not retroactively change an existing one.
Only one hostname fails
- Check hostname coverage, expiration, issuer, and intermediate certificates on that server. Fix the deployment or provide its intended internal root.
Every HTTPS site fails
- Investigate proxy interception, antivirus HTTPS scanning, incorrect system time, and enterprise Firefox policy. Compare a clean network or unmanaged browser only with authorization.
Local works but remote fails
- Inspect the remote node’s Firefox profile, trust store, proxy settings, DNS, clock, and geckodriver logs. Your local certificate store is not evidence that the remote node trusts the same authority.
The browser crashes or the session will not start
- Record Selenium, binding, Firefox, and geckodriver versions, then compare them with the Selenium Firefox requirements. Avoid attributing the failure to a particular driver release unless your environment’s logs establish it.
A safer test design
- Keep a normal-validation suite for public and production-like endpoints.
- Use a separate fixture with
acceptInsecureCertsonly for intentionally invalid staging certificates. - Label those tests clearly so a passing result cannot be mistaken for proof that the certificate is valid.
- When a certificate is expected to be trusted, install the approved root in the browser profile instead of accepting all invalid certificates.
- Capture the error code, URL, environment, and session capabilities in failure reports.
Or skip the browser setup
If your goal is simply to obtain a clean image or PDF of a page rather than exercise Firefox certificate behavior, ScreenshotNeo provides a single HTTP request. Its capture pipeline accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before the shot; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result. It also offers an MCP server with take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.
See the ScreenshotNeo documentation for all options. cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Every plan includes the features: the free tier provides 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for the free ScreenshotNeo account.
Frequently asked questions
Does acceptInsecureCerts install a certificate?
No. It changes validation behavior for one WebDriver session; it does not modify Firefox’s trust store or repair the server chain.
Can I enable it for only one URL?
No. The capability applies to the whole session. Create a separate driver when you need different certificate-validation behavior.
Best Value
Why does a public site work manually but fail in automation?
Compare the exact Firefox profile, proxy, DNS path, system clock, and remote host. Automation may be running on a different machine or under an enterprise policy.
Frequently Asked Questions
Does acceptInsecureCerts install a certificate?
No. It changes validation behavior for one WebDriver session; it does not modify Firefox’s trust store or repair the server chain.
Can I enable it for only one URL?
No. The capability applies to the whole session. Create a separate driver when you need different certificate-validation behavior.
Why does a public site work manually but fail in automation?
Compare the exact Firefox profile, proxy, DNS path, system clock, and remote host. Automation may be running on a different machine or under an enterprise policy.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

