Why a certificate at all

HTTPS is encrypted end-to-end by design. For Hollowport to show you the actual method, headers, and body of a request — not just that a connection happened — your device needs to trust a certificate authority that can see inside it. That's not a Hollowport-specific requirement; it's how every HTTPS-inspecting tool works on any platform, because it's how TLS itself works.

The certificate's private key is generated on your device the first time you need it and stored in the device Keychain, specifically excluded from iCloud Keychain sync and from unencrypted backups. It never leaves your phone, and nothing is routed through a server Hollowport or Hevexa operates.

Install the profile

  1. Open More → Certificate inside Hollowport.
  2. Tap Install Profile. iOS hands control to the Settings app for this part — that's expected, and it's how every configuration profile gets installed on iOS, not something Hollowport can do without leaving the app.
  3. iOS switches to the Settings app on its own and drops you straight onto a Profile Downloaded screen — there's nothing to navigate to yourself. Tap Allow, then Install in the top-right corner twice (once for the warning screen, once to confirm). Enter your device passcode if asked.
  4. If Settings doesn't open automatically, or you close it before finishing, go to Settings → General → VPN & Device Management and tap the Hollowport profile waiting there to pick up where you left off.
  5. Return to Hollowport. The Certificate screen should now show the profile as installed.

Turn on full trust

Installing the profile isn't enough by itself — iOS treats a newly installed certificate as untrusted for actually decrypting traffic until you flip one more switch:

  1. Go to Settings → General → About → Certificate Trust Settings.
  2. Find Hollowport in the list under "Enable Full Trust for Root Certificates."
  3. Toggle it on, and confirm the warning dialog.

Nothing decrypts until both steps are done

Skip either step and Hollowport still sees that connections happened — host, timing, whether it succeeded — but every HTTPS request shows up opaque instead of readable. If your capture is full of unreadable rows, this is almost always why.

Troubleshooting

"Hollowport" doesn't appear in Certificate Trust Settings

Go back and confirm the profile actually finished installing under Settings → General → VPN & Device Management. If it's not listed there, the install in the previous section didn't complete — repeat it from Hollowport's Certificate screen.

The toggle won't turn on, or Settings shows a restriction

This is the standard MDM/supervision restriction, not a Hollowport bug. On a company- or school-managed device, installing a trusted root certificate is often blocked by policy. Check with whoever manages the device.

Traffic still looks encrypted after both steps

Force-quit and reopen the app you're testing — some apps cache their TLS session before the certificate was trusted. If it's still opaque after that, confirm you're capturing that app's traffic at all (see First Capture), and check whether the app pins its certificate — see the note in Traffic View on what pinning looks like and why it can't be bypassed, or the full Capabilities & Limitations reference for the complete technical picture.

Removing trust

Delete the profile any time under Settings → General → VPN & Device Management. Decryption stops immediately, and Hollowport can no longer read HTTPS content — the same as if it were never installed.