Analyze Connector Traffic
Developer troubleshooting
Route NIM connector traffic through Fiddler to inspect requests and responses while diagnosing REST or PowerShell connectors.
Fiddler can decrypt HTTPS traffic and expose credentials or personal data. Use this procedure only on a secured test machine, restrict access to the capture, and remove the proxy configuration when troubleshooting is complete.
Set up the debugging proxyDirect link to Set up the debugging proxy
1. Install FiddlerDirect link to 1. Install Fiddler
Install the latest Fiddler Classic web debugger on the same machine that will run the proxy. Open Fiddler and leave it running throughout the test.
Outcome: Fiddler is ready to receive local proxy traffic.
2. Trust the local inspection certificateDirect link to 2. Trust the local inspection certificate
- In Fiddler, open Tools → Options → HTTPS.
- Enable Capture HTTPS CONNECTs and Decrypt HTTPS traffic.
- Accept each prompt to trust and install the Fiddler root certificate.
Only trust the certificate on the controlled troubleshooting machine. Treat it like a sensitive debugging credential.
3. Export the certificate for NIMDirect link to 3. Export the certificate for NIM
- In Fiddler, choose Actions → Export Root Certificate to Desktop.
- Move the exported
.cerfile to a protected, stable location, such asC:\Tools4ever\certs\FiddlerRoot.cer. - In Options → General, disable Enable IPv6, then restart Fiddler.
- Under Protocols, add
tls1.1;tls1.2if your troubleshooting environment requires those protocols.
Outcome: NIM can be configured to trust Fiddler's local HTTPS inspection certificate.
4. Configure the NIM serviceDirect link to 4. Configure the NIM service
Add these values under the NIM service environment registry key. Update the certificate path to match your exported file.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NIM\env]
"NODE_EXTRA_CA_CERTS"="C:\\Tools4ever\\certs\\FiddlerRoot.cer"
"NODE_TLS_REJECT_UNAUTHORIZED"="0"
Restart the NIM service after applying the change.
NODE_TLS_REJECT_UNAUTHORIZED=0 weakens TLS validation. Use it only temporarily for troubleshooting and remove it immediately after the capture.
5. Route connector traffic, inspect it, and remove the proxyDirect link to 5. Route connector traffic, inspect it, and remove the proxy
- In NIM system configuration, enable the proxy and set it to
http://127.0.0.1:8888. - Run the REST or PowerShell connector action you need to diagnose.
- In Fiddler, inspect the request URL, headers, body, response status, and response payload.
- Disable the NIM proxy, remove the temporary TLS environment settings, and restart NIM when finished.
Outcome: You have the diagnostic traffic you need without leaving a debugging proxy or weakened TLS configuration enabled.