How to install Windows 10 root certificates
Root certificates are public key certificates that help your browser determine whether communication with a website is genuine and is based upon whether the issuing authority is trusted and if the digital certificate remains valid. If a digital certificate is not from a trusted authority, you’ll get an error message along the lines of “There is a problem with this website’s security certificate” and the browser might block communication with the website.
Windows 10 has built-in certificates and automatically updates them. However, you can still manually add more root certificates to Windows 10 from certificate authorities (CAs). There are numerous certificate issuing authorities, with Comodo and Symantec among the best known. This is how you can add digital certificates to Windows 10 from trusted CAs.
- First, you’ll need to download a root certificate from a CA. For example, you could download one from the GeoTrust site.
- Next, open Local Security Policy in Windows by pressing the Win key + R hotkey and entering ‘secpol.msc’ in Run’s text box. Note that Windows 10 Home edition doesn’t include the Local Security Policy editor.
- Then, click Public Key Policies and Certificate Path Validation Settings to open a Certificate Path Validation Settings Properties window.
- Click the Stores tab and select the Define these policy settings check box.
- Select the Allow user trusted root CAs to be used to validate certificates and Allow users to trust peer trust certificates options if they’re not already selected.
- You should also select the Third-Party Root CAs and Enterprise Root CAs checkbox and press the Apply > OK buttons to confirm the selected settings.
- Next, press the Win key + R hotkey and enter ‘certmgr.msc’ in Run’s text box to open the window shown in the snapshot directly below. That’s the Certification Manager which lists your digital certificates.
- Click Trusted Root Certification Authorities and right-click Certificates to open a context menu.
- Select All Tasks > Import on the context menu to open the window shown below.
- Press the Next button, click Browse, and then select the digital certificate root file saved to your HDD.
- Press Next again to select the Automatically select the certificate store based on the type of certificate option.
- Then you can press Next > Finish to wrap up the import wizard. A window will open confirming that “the import was successful.”
Install Certificates with the Microsoft Management Console
- You can also add digital certificates to Windows with the Microsoft Management Console. Press the Win key + R hotkey and input ‘mmc’ in Run to open the window below.
- Click File and then select Add/Remove Snap-ins to open the window in the snapshot below.
- Next, you should select Certificates and press the Add button.
- A Certificates Snap-in window opens from which you can select Computer account > Local Account, and press the Finish button to close the window.
- Then press the OK button in the Add or Remove Snap-in window.
- Now you can select Certificates and right-click Trusted Root Certification Authorities on the MMC console window as below.
- Then you can click All Tasks > Import to open the Certificate Import Wizard window from which you can add the digital certificate to Windows.
Now you’ve installed a new trusted root certificate in Windows 10. You can add many more digital certificates to that OS and other Windows platforms in a similar manner. Just make sure that the third-party digital certificates come from trusted CAs, such as GoDaddy, DigiCert, Comodo, GlobalSign, Entrust and Symantec.
Microsoft is all set to launch its next big update, Windows 10 version 1809 in October. While that should be a nice piece of news […]
The Windows 10 October 2018 Update (otherwise 18H2) rollout might now be two to three weeks away. For the last few months, new build previews […]