Egern · WLOC setup tutorial
Set up WLOC on Egern — Surge-format module, own CA, and MitM, step by step
Egern and Surge share the same module format. That is where the similarity ends. The CA certificate from Surge will not work in Egern. It will not even throw an error — MitM just silently fails. Generate a fresh CA inside Egern, install it, and trust it independently. Each app's CA is cryptographically tied to that app. Do not try to shortcut this.
Before you start
- WLOC installed.
- Egern installed (separate purchase).
- A test device.
- Stable Wi-Fi.
Step 1: Import the Surge-format module into Egern
Copy the URL: https://wloc.app/modules/wloc.sgmodule. In Egern, Module section, tap +, paste URL, import. WLOC does not generate a separate file for Egern.
- Egern accepts Surge-format modules.
- Verify module appears and is toggled ON.
Step 2: Generate Egern's own CA — do not reuse another client's
Critical step. Do NOT reuse a CA from Surge or any other client. Egern Settings → MitM → Generate CA. Install profile. iOS trust: Settings → General → About → Certificate Trust Settings → toggle ON for Egern CA.
- Generate Egern's OWN CA — not Surge's, not anyone else's.
- CA generation: Egern Settings → MitM → Generate CA.
- iOS trust: Settings → General → About → Certificate Trust Settings.
Step 3: Verify with WLOC diagnostics
Save a test target. Run diagnostics. Because Egern uses the Surge-format module, diagnostic output mirrors Surge behavior. Look for patch count > 0.
- Patch count > 0 confirms the script is running.
- Diagnostic behavior mirrors Surge — same module format.
Step 4: Restore: clear, disable module, revoke CA
WLOC: clear target. Egern: toggle module OFF, disable MitM. iOS: remove CA profile. Module can stay imported.
- Toggle module OFF, then disable MitM.
- Remove CA profile from iOS Settings.
Common gotchas
Reusing a CA from another client
Each app's CA is tied to that specific app. If you try Surge's CA with Egern, MitM silently fails. Delete the wrong CA, generate a new one inside Egern, install, and trust it. Do not try to shortcut this.
FAQ
Can I share a CA between Egern and Surge?
No. Each app's CA is generated inside that specific app and is cryptographically tied to it. You must generate, install, and trust a separate CA for Egern.