Skip to content

Trusting Your Root CA on Mac

Sahil Phule edited this page Oct 17, 2024 · 2 revisions
  1. Ensure you have downloaded your Root CA

  2. Locate your downloaded Root CA. Right click it and select Show in Folder

  3. Finder will open. Locate your root-ca.crt file in your Downloads folder and double click it to import it into the Keychain Access program. You will be prompted for your macOS username and password, or thumbprint. Then select Modify Keychain: image

  4. Press Command + Spacebar to launch a program, type in Keychain Access and select the resulting Keychain Access program to open it. image

  5. Your server’s CA certificate will be displayed among the imported certificates in Keychain Access. Right-click on the imported CA cert and select Get Info: image

  6. The details of your CA certificate will be displayed in a new dialog window. Expand the Trust heading, then select “Always Trust” on Secure Sockets Layer (SSL) and X.509 Basic Policy. image

Click the red (x) button at the top left of the Local Root CA dialog window.

7. You will then be prompted again for your username and password, or thumbprint. Enter those and click Update Settings: image

  1. You will see your server’s CA certificate as trusted now, signified by a blue (+) sign and the CA cert information will now say “This certificate is marked as trusted for all users” in Keychain Access: image

Tip: If the keychain console did not show the certificate as trusted, press “Command + spacebar” and type “Keychain Access”, and hit enter to re-open it.

  1. If using Firefox or TorBrowser, complete this final step


Reference