Fix Clipchamp Cannot Sign In Through a Kerberos Proxy
Question details
The user is unable to sign in to a work account in Clipchamp version 3 when connected through a corporate proxy using Kerberos authentication.

- Product
- Clipchamp
- Device & OS
- not provided
- Scenario
- Attempting to log into a work account via Clipchamp within a corporate network environment that strictly enforces Kerberos proxy authentication and SSL inspection.
- Observed behavior
- The sign-in process fails completely. However, other Microsoft applications function normally, and disabling authentication for selected Microsoft domains temporarily restores Clipchamp's sign-in capability.
Ensure you have administrative privileges or are able to coordinate with your IT network and security teams, as resolving this requires modifying corporate proxy policies and SSL interception rules.
Exclude Clipchamp and Microsoft Graph from SSL Interception
Bypass SSL inspection on your corporate proxy for specific Microsoft domains to prevent certificate pinning conflicts during the Clipchamp sign-in handshake.
Clipchamp version 3 utilizes strict certificate pinning to secure its connection to Microsoft services. When a corporate proxy with SSL interception is active, it replaces the certificate, causing an SSL handshake failure with graph.microsoft.com.
Log in to your enterprise proxy server or firewall administration console using an administrator account.
Navigate to the SSL interception rules and add graph.microsoft.com to the bypass or exclusion list.
Ensure that the primary Clipchamp application domains are also added to the SSL inspection bypass policy.
Save the new proxy policies, restart the Clipchamp application on the client machine, and attempt to sign in to the work account.

Escalate to Microsoft Enterprise Support
If adjusting SSL interception does not resolve the issue, advanced Kerberos authentication debugging may be required.
Looking for a Hassle-Free Office Suite? Try WPS Office
While resolving complex network proxy and authentication issues for certain Microsoft applications, consider using WPS Office for your everyday document needs. It offers a lightweight, seamless experience that doesn't rely on complicated corporate network configurations for robust offline work.
- 1. Download the Software: Visit the official WPS Office website and download the free installation package.
- 2. Install WPS Office: Run the installer and follow the simple on-screen prompts to complete the setup.
- 3. Start Working Instantly: Open the application to immediately begin editing your documents, spreadsheets, and presentations without complex sign-in hurdles.

Frequently Asked Questions
Why does Clipchamp version 3 fail to sign in when version 2 worked perfectly?
Clipchamp version 3 introduced work-account support and changed how content syncs with OneDrive. These updates utilize strict certificate pinning, which frequently conflicts with corporate proxy servers performing SSL interception.
Which specific domains need to be excluded from SSL inspection?
To resolve the most common handshake failures, you typically need to bypass SSL interception for graph.microsoft.com alongside the main Clipchamp application domains.
Can I bypass the proxy entirely for Clipchamp?
If your network architecture allows split-tunneling or direct internet access for specific applications, routing Clipchamp traffic directly to the internet bypassing the Kerberos proxy will also resolve the sign-in error.




