Fix Puppeteer Screenshots of Indian Bank Websites That Show a Certificate Error
Find the cause of a Puppeteer certificate interstitial and fix the runtime’s trust problem safely. Never bypass the warning to capture banking credentials.
A Puppeteer screenshot that shows a certificate warning usually means Chromium could not validate the HTTPS connection using the trust and identity checks in effect for that browser runtime. The screenshot may be faithfully showing Chromium’s certificate interstitial; that does not by itself prove Puppeteer rendered incorrectly or that the bank’s certificate is defective.
For a real banking site, do not enter credentials while a certificate warning is present, and do not silently bypass it to create a clean-looking image. Diagnose and repair the trust or configuration problem first. Puppeteer’s acceptInsecureCerts option can ignore HTTPS errors, but it does not repair the certificate or authenticate the bank.
1. Capture the evidence before changing settings
Record the error code, final URL, runtime versions, and certificate chain from the same machine or container that runs Puppeteer. The exact hostname and net::ERR_CERT_* code are needed for a site-specific diagnosis; there is no basis here to say which bank host or certificate is affected.
- Log the complete navigation exception and the URL after redirects.
- Record Puppeteer, Chromium, operating system or container image, and system date and time.
- Inspect the certificate chain from inside the same runtime: hostname names, validity dates, intermediates, and issuer/root trust.
- Check whether a corporate proxy or TLS inspection system terminates and reissues HTTPS connections.
- Compare with a separate, current browser/runtime as a clue. A difference does not, by itself, establish which endpoint is trustworthy.
Chromium’s root-store FAQ documents a case in which some users saw NET::ERR_CERT_AUTHORITY_INVALID during a root-store and verifier rollout. Trust-store behavior can therefore matter; do not diagnose every warning as a bank-side defect. Chromium certificate verifier and root store FAQ.
2. Diagnose by the certificate and final host
Certificate validation happens during navigation, before a normal page is available to capture. A redirect can change the host being checked, so inspect the final URL as well as the original URL.
| Check | What to verify | Typical next step |
|---|---|---|
| Error code | Capture the exact net::ERR_CERT_… string. |
Use it to narrow the issue; the generic interstitial alone is insufficient. |
| Hostname | The final URL host must match a certificate subject alternative name. | Check the URL and redirects; correct a wrong host or escalate a genuine mismatch. |
| Validity | Certificate dates must include the machine’s current time. | Correct the system clock if wrong; otherwise the certificate owner must renew or replace an expired/not-yet-valid certificate. |
| Chain | The server should supply required intermediate certificates and the runtime should trust a valid root. | Repair the server chain or install the organization’s approved trust root in the runtime, as appropriate. |
| Proxy / TLS inspection | Check whether the observed issuer is an organization proxy rather than the expected public issuer. | Use the approved proxy configuration and trust setup; do not disable verification to conceal interception. |
| Runtime differences | Compare the chain and result on the same host in another maintained runtime. | Update the browser or runtime trust configuration when evidence points there. |
Indian Bank advises customers to type its official URL directly, check the address and SSL lock, and keep the browser current. That is useful security guidance, not evidence about the current certificate status of any other bank or hostname. Indian Bank official site. Its 2024 cyber-security audit document includes TLS version/algorithm and certificate-validity checks as audit controls; those controls are a checklist, not proof of a target site’s present state. Indian Bank cyber-security audit report.
3. Reproduce the navigation with Puppeteer
This runnable Node.js example logs key diagnostics and attempts a screenshot only if navigation reaches an ordinary page. It deliberately keeps normal certificate verification enabled. Save as capture.js in a project where Puppeteer is installed, then run node capture.js https://example.com/ with a URL you are authorized to inspect.
const puppeteer = require('puppeteer');
(async () => {
const target = process.argv[2];
if (!target) throw new Error('Usage: node capture.js https://host/');
const browser = await puppeteer.launch({ headless: true });
try {
const page = await browser.newPage();
page.on('requestfailed', request => {
console.error('requestfailed', request.url(), request.failure()?.errorText);
});
page.on('console', message => {
if (message.type() === 'error') console.error('console', message.text());
});
try {
const response = await page.goto(target, {
waitUntil: 'domcontentloaded',
timeout: 45000
});
console.log(JSON.stringify({
requestedUrl: target,
finalUrl: page.url(),
status: response?.status() ?? null,
puppeteer: require('puppeteer/package.json').version,
browser: await browser.version()
}, null, 2));
await page.screenshot({ path: 'capture.png', fullPage: true });
} catch (error) {
console.error('Navigation failed:', error.message);
console.error(JSON.stringify({
requestedUrl: target,
currentUrl: page.url(),
puppeteer: require('puppeteer/package.json').version,
browser: await browser.version(),
systemTime: new Date().toISOString()
}, null, 2));
throw error;
}
} finally {
await browser.close();
}
})().catch(error => {
console.error(error);
process.exitCode = 1;
});
For a failing certificate navigation, the thrown message commonly includes the Chromium network error. Preserve the full message and inspect the chain in the same environment. The script does not print private keys or browser profile data.
4. Repair trust and runtime configuration
- Correct the host or redirect target if it is not the intended site.
- Correct the system clock if its date or time is wrong.
- Update the Puppeteer-managed browser/runtime and operating system trust data through the normal deployment process.
- If TLS inspection is required, configure the organization-approved proxy and trusted certificate chain for the runtime. Ask the network/security administrator for the correct CA distribution method.
- If the certificate is expired, mismatched, or the server omits an intermediate, report the exact hostname, error, and observed chain to the site operator.
- Repeat the capture with verification enabled and confirm the final URL and certificate are valid before treating the result as trustworthy.
A Puppeteer browser bundle and the host’s system tools can use different trust configuration, so a successful command-line check outside the container does not necessarily demonstrate that Chromium inside it trusts the chain. Inspect from within the actual deployment environment.
5. Controlled exception for non-sensitive test captures
Puppeteer’s ConnectOptions reference documents acceptInsecureCerts as “Whether to ignore HTTPS errors during navigation.” Its documented default is false. This changes browser acceptance behavior; it does not fix the certificate or prove the server identity. Use it only for an isolated test fixture or explicitly trusted, non-sensitive capture context. Never use it to submit banking credentials or capture a real banking session. Puppeteer ConnectOptions reference.
const puppeteer = require('puppeteer');
(async () => {
const browser = await puppeteer.launch({
headless: true,
acceptInsecureCerts: true // Test fixtures only; never for online banking.
});
try {
const page = await browser.newPage();
await page.goto('https://your-controlled-test-host.example/', {
waitUntil: 'domcontentloaded',
timeout: 45000
});
await page.screenshot({ path: 'test-fixture.png', fullPage: true });
} finally {
await browser.close();
}
})().catch(error => {
console.error(error);
process.exitCode = 1;
});
Use a disposable process and test data. Remove the option as soon as the test no longer requires it. Do not make it a global production default or combine it with credential entry.
6. Distinguish certificate failures from other browser errors
net::ERR_BLOCKED_BY_CLIENT is not a certificate validation error. Puppeteer’s troubleshooting page discusses this error in relation to Chrome’s HTTP-first warning feature; that workaround does not remedy an HTTPS certificate failure. First classify the actual network error, then use the relevant troubleshooting path. Puppeteer troubleshooting.
7. Troubleshooting common symptoms
| Symptom | Likely direction | Action |
|---|---|---|
ERR_CERT_AUTHORITY_INVALID |
Untrusted issuer/root, missing trust data, or an intercepting proxy are possibilities. | Inspect the observed issuer and full chain inside the runtime; verify approved root trust. |
ERR_CERT_COMMON_NAME_INVALID or a name mismatch |
The final host may not appear in the certificate names, or a redirect may lead elsewhere. | Log the final URL and compare it with certificate subject alternative names. |
ERR_CERT_DATE_INVALID |
Wrong system time or certificate validity dates outside the current time. | Check UTC time and certificate dates; correct the clock or contact the certificate owner. |
| Warning appears only in a container | Different CA bundle, browser build, proxy route, or clock. | Run diagnostics inside the container and compare its chain and trust configuration. |
| Navigation times out without a certificate code | Connectivity, page load, or another navigation condition may be responsible. | Log failed requests and final URL; do not infer a certificate issue from a timeout alone. |
ERR_BLOCKED_BY_CLIENT |
Client-side browser behavior or policy, distinct from TLS certificate validation. | Follow Puppeteer’s troubleshooting guidance for that exact error; do not apply certificate bypass as a fix. |
| Screenshot contains a Chromium warning page | Navigation reached the certificate interstitial. | Preserve it as diagnostic evidence, then resolve the trust/identity cause before capturing sensitive content. |
8. Performance, reliability, and cost
Certificate verification is part of establishing the HTTPS connection. Disabling checks may let a test proceed, but it makes the result less reliable as evidence of the real site’s identity. It is not a performance optimization for a real banking capture.
- Reliability: pin the Puppeteer and browser deployment versions, keep the operating system and trust roots current, and capture the exact environment details when failures occur.
- Timeouts: choose a finite navigation timeout and log whether failure was a timeout or a certificate error. A timeout is not proof of a TLS problem.
- Repeatability: record requested and final URLs, runtime versions, UTC clock, and chain details with each diagnostic run.
- Cost: local Puppeteer has no per-screenshot API charge, but the browser and infrastructure consume compute and maintenance time. Avoid repeated captures until the trust issue is understood.
- Security: treat certificate warnings on banking sites as a stop signal for credentials and sensitive data.
9. Or skip the browser setup
ScreenshotNeo is a website screenshot API and MCP server from Yorker Media. It accepts a URL in one GET request and returns a PNG, JPEG, WebP, or PDF. Its capture flow accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Only clean shots are billed: bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses identify the page verdict and billing status in headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf for Claude, Cursor, and other MCP clients. It does not make an unsafe certificate warning safe: do not use any capture service to enter bank credentials through a certificate interstitial.
Start with the ScreenshotNeo API documentation. Replace the example URL with a public page you are authorized to capture, and use your API key:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
const fs = await import('node:fs/promises');
await fs.writeFile('shot.webp', Buffer.from(await res.arrayBuffer()));
Cookie banners, popups, and chat widgets are removed before the shot. Bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Sign up for 1,000 free screenshots a month, no card required.
10. FAQ
Does a certificate interstitial mean Puppeteer is broken?
No. Chromium may be correctly displaying the result of its HTTPS validation. The cause can be in the host, chain, trust store, clock, redirect, or proxy path.
Can I use ignoreHTTPSErrors in Puppeteer?
Use the documented acceptInsecureCerts setting for controlled, non-sensitive tests only. It ignores errors; it does not authenticate the endpoint.
Can the available evidence identify which Indian bank is at fault?
No hostname or live certificate chain was supplied. A precise diagnosis requires the target host, exact error, runtime details, and chain seen inside that runtime.
Does a successful screenshot prove a bank page is safe?
No. A screenshot is an image of rendered content, not a certificate audit or assurance that a page is legitimate.


