Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Firefox’s insecure-connection page means certificate validation failed. First record the exact error code and determine whether one site or many sites are affected. For a controlled test target whose invalid certificate is expected, create the WebDriver session with acceptInsecureCerts set to true. That permits navigation for the entire session; it does not repair the certificate. For production-like testing, fix the server chain or install the correct trust anchor instead.

What the Firefox error means

Firefox checks a website certificate to verify the site and protect the encrypted connection. An insecure-connection warning therefore identifies a failed validation check, not automatically the cause. The warning page’s code is the most useful starting point.

Common codes

  • SEC_ERROR_UNKNOWN_ISSUER: Firefox cannot establish trust in the certificate issuer.
  • MOZILLA_PKIX_ERROR_MITM_DETECTED: the certificate resembles one produced by an intercepting authority that Firefox does not trust.
  • ERROR_SELF_SIGNED_CERT: the certificate is self-signed and is not trusted by the browser.

A failure on one hostname usually points to that server’s certificate, chain, or intermediate configuration. Failures on many unrelated HTTPS sites suggest a work-network proxy, antivirus TLS scanning, another interception device, or a machine-wide trust problem.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Diagnose before changing Selenium

  1. Run the navigation manually in the same Firefox installation and record the complete URL, warning text, and error code.
  2. Try two or three unrelated HTTPS sites. Keep the scope: one site and one certificate problem require a different fix from a browser that rejects nearly everything.
  3. For a single site, inspect the certificate’s subject, issuer, validity dates, and intermediate chain. A missing intermediate is a common server-side cause.
  4. For multiple sites, ask whether a corporate proxy or antivirus product deliberately intercepts TLS. Obtain the organization’s approved root certificate and trust procedure rather than accepting arbitrary certificates.
  5. Note Selenium, Firefox, geckodriver, and language-binding versions, and whether the browser runs locally or on a remote grid. Selenium’s Firefox documentation states that Selenium 4 requires Firefox 78 or newer and recommends the latest geckodriver; it does not provide one universal compatibility matrix for every release combination.

Use acceptInsecureCerts for a controlled test

acceptInsecureCerts is a standard WebDriver session capability. When false, an invalid certificate can make navigation return a certificate error. When true, the browser accepts invalid certificates for that newly created session. The setting is session-wide, so it is not a per-URL switch.

Python with Selenium

Install Selenium in the environment that will launch Firefox, then create the option before constructing the driver:

from selenium import webdriver
from selenium.webdriver.firefox.options import Options

options = Options()
options.accept_insecure_certs = True

driver = webdriver.Firefox(options=options)
try:
    driver.get("https://staging.example.test")
    print(driver.title)
finally:
    driver.quit()

The URL is an example; replace it with your controlled test host. Keep this configuration in a test-specific fixture or profile, not in a shared default used for security or certificate-regression tests.

Remote Python session

Pass the same options object when creating the remote session. The browser host, not your laptop, must have the required Firefox and geckodriver setup:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
from selenium import webdriver
from selenium.webdriver.firefox.options import Options

options = Options()
options.accept_insecure_certs = True

driver = webdriver.Remote(
    command_executor="http://grid-host:4444/wd/hub",
    options=options,
)
try:
    driver.get("https://staging.example.test")
finally:
    driver.quit()

A local Firefox profile or trust store is not automatically copied to a remote browser. Configure certificates on the machine that actually runs Firefox, or provide a profile through the grid’s supported capabilities.

JavaScript and Java capability shape

Client syntax varies by binding and release, but the capability being sent is the same. In JavaScript, set the Firefox option when building the driver:

const { Builder } = require('selenium-webdriver');
const firefox = require('selenium-webdriver/firefox');

const options = new firefox.Options();
options.setAcceptInsecureCerts(true);

(async () => {
  const driver = await new Builder()
    .forBrowser('firefox')
    .setFirefoxOptions(options)
    .build();
  try {
    await driver.get('https://staging.example.test');
  } finally {
    await driver.quit();
  }
})();

For Java, Ruby, and other clients, use that binding’s current Firefox options API to send the standard acceptInsecureCerts: true capability. Verify the generated session capabilities in your grid logs if the setting appears to have no effect.

When accepting the certificate is the wrong fix

Repair a site you control

Install a certificate valid for the hostname, serve the complete intermediate chain, and ensure the system clock is correct. A browser bypass can hide a broken deployment that real users will reject. Keep at least one test path that validates certificates normally so a renewal or chain regression is detected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Trust an intentional internal authority

In a controlled laboratory or corporate network, a proxy may intentionally re-sign traffic. Ask the network administrator for the approved interception root and install it in Firefox’s trust configuration or supply it through a managed profile. Do not import an unknown certificate merely to make a test pass.

Understand the security and fidelity trade-off

Session-wide acceptance allows navigation despite an invalid certificate, reducing protection during that run. It also means the test cannot detect certificate-chain failures that users would encounter. Use it only when certificate validation is outside the test’s purpose and the target is controlled.

Firefox cases where a bypass is unavailable

The manual “Accept the Risk and Continue” control can be absent for HSTS sites, certain critical certificate errors, or enterprise-managed Firefox installations that disable bypasses. This is expected behavior, not a Selenium defect. Identify the certificate condition and configure the intended trust relationship; do not attempt to automate around an HSTS policy by default.

Profiles, preferences, and certificates

Selenium’s Python Firefox options support preferences through set_preference, and Firefox options can carry a profile with custom certificates. Use these mechanisms only for a certificate authority your test environment is supposed to trust. The exact profile and certificate must be available on the remote browser host when execution is distributed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
from selenium import webdriver
from selenium.webdriver.firefox.options import Options

options = Options()
options.set_preference("network.trr.mode", 5)  # example preference; use only when required
# Supply a managed profile or certificate using your grid's documented method.
driver = webdriver.Firefox(options=options)
try:
    driver.get("https://internal.example.test")
finally:
    driver.quit()

Do not copy this example preference into every suite without understanding its network effect. Certificate installation is environment-specific; coordinate with the administrator who owns the trust policy.

Troubleshooting checklist

The warning remains after setting the option

  • Confirm the option was attached before webdriver.Firefox(...) or webdriver.Remote(...); changing it after session creation cannot alter that session’s capability.
  • Make sure the test is using the intended driver and browser, not a separately launched Firefox process.
  • Inspect the new session’s capabilities in driver or grid logs and check that the remote node received acceptInsecureCerts: true.
  • Reproduce with a fresh session; capabilities do not retroactively change an existing one.

Only one hostname fails

  • Check hostname coverage, expiration, issuer, and intermediate certificates on that server. Fix the deployment or provide its intended internal root.

Every HTTPS site fails

  • Investigate proxy interception, antivirus HTTPS scanning, incorrect system time, and enterprise Firefox policy. Compare a clean network or unmanaged browser only with authorization.

Local works but remote fails

  • Inspect the remote node’s Firefox profile, trust store, proxy settings, DNS, clock, and geckodriver logs. Your local certificate store is not evidence that the remote node trusts the same authority.

The browser crashes or the session will not start

  • Record Selenium, binding, Firefox, and geckodriver versions, then compare them with the Selenium Firefox requirements. Avoid attributing the failure to a particular driver release unless your environment’s logs establish it.

A safer test design

  1. Keep a normal-validation suite for public and production-like endpoints.
  2. Use a separate fixture with acceptInsecureCerts only for intentionally invalid staging certificates.
  3. Label those tests clearly so a passing result cannot be mistaken for proof that the certificate is valid.
  4. When a certificate is expected to be trusted, install the approved root in the browser profile instead of accepting all invalid certificates.
  5. Capture the error code, URL, environment, and session capabilities in failure reports.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is simply to obtain a clean image or PDF of a page rather than exercise Firefox certificate behavior, ScreenshotNeo provides a single HTTP request. Its capture pipeline accepts cookie or consent banners and removes more than 60 known consent platforms, newsletter popups, and chat widgets before the shot; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result. It also offers an MCP server with take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients.

See the ScreenshotNeo documentation for all options. cURL:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Every plan includes the features: the free tier provides 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for the free ScreenshotNeo account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently asked questions

Does acceptInsecureCerts install a certificate?

No. It changes validation behavior for one WebDriver session; it does not modify Firefox’s trust store or repair the server chain.

Can I enable it for only one URL?

No. The capability applies to the whole session. Create a separate driver when you need different certificate-validation behavior.

Why does a public site work manually but fail in automation?

Compare the exact Firefox profile, proxy, DNS path, system clock, and remote host. Automation may be running on a different machine or under an enterprise policy.

Frequently Asked Questions

Does acceptInsecureCerts install a certificate?

No. It changes validation behavior for one WebDriver session; it does not modify Firefox’s trust store or repair the server chain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I enable it for only one URL?

No. The capability applies to the whole session. Create a separate driver when you need different certificate-validation behavior.

Why does a public site work manually but fail in automation?

Compare the exact Firefox profile, proxy, DNS path, system clock, and remote host. Automation may be running on a different machine or under an enterprise policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.