Root certificates are public key certificates that help your browser determine whether communication with a website is genuine and is based upon whether the issuing authority is trusted and if the digital certificate remains valid.
If a digital certificate is not from a trusted authority, you’ll get an error message along the lines of “There is a problem with this website’s security certificate” and the browser might block communication with the website.
Windows 10 has built-in certificates and automatically updates them. However, you can still manually add more root certificates to Windows 10 from certificate authorities (CAs).
There are numerous certificate issuing authorities, with Comodo and Symantec among the best known.
How can I add Windows 10 root certificates manually?
Method 1: Install certificates from trusted CAs
This is how you can add digital certificates to Windows 10 from trusted CAs.
- First, you’ll need to download a root certificate from a CA. For example, you could download one from the GeoTrust site.
- Next, open Local Security Policy in Windows by pressing the Win key + R hotkey and entering ‘secpol.msc’ in Run’s text box. Note that Windows 10 Home edition doesn’t include the Local Security Policy editor. If your Windows key doesn’t work, check this quick guide to fix it.
- Then, click Public Key Policies and Certificate Path Validation Settings to open a Certificate Path Validation Settings Properties window.
- Click the Stores tab and select the Define these policy settings check box.
- Select the Allow user trusted root CAs to be used to validate certificates and Allow users to trust peer trust certificates options if they’re not already selected.
- You should also select the Third-Party Root CAs and Enterprise Root CAs checkbox and press the Apply > OK buttons to confirm the selected settings.
- Next, press the Win key + R hotkey and enter ‘certmgr.msc’ in Run’s text box to open the window shown in the snapshot directly below. That’s the Certification Manager which lists your digital certificates.
- Click Trusted Root Certification Authorities and right-click Certificates to open a context menu.
- Select All Tasks > Import on the context menu to open the window shown below.
- Press the Next button, click Browse, and then select the digital certificate root file saved to your HDD.
- Press Next again to select the Automatically select the certificate store based on the type of certificate option.
- Then you can press Next > Finish to wrap up the import wizard. A window will open confirming that “the import was successful.”
Most Windows 10 users have no idea how to edit the Group Policy. Learn how you can do it by reading this simple article.
Expert Tip: Some PC issues are hard to tackle, especially when it comes to corrupted repositories or missing Windows files. If you are having troubles fixing an error, your system may be partially broken. We recommend installing Restoro, a tool that will scan your machine and identify what the fault is.
Click here to download and start repairing.
Method 2: Install Certificates with the Microsoft Management Console
- You can also add digital certificates to Windows with the Microsoft Management Console. Press the Win key + R hotkey and input ‘mmc’ in Run to open the window below.
- Click File and then select Add/Remove Snap-ins to open the window in the snapshot below.
- Next, you should select Certificates and press the Add button.
- A Certificates Snap-in window opens from which you can select Computer account > Local Account, and press the Finish button to close the window.
- Then press the OK button in the Add or Remove Snap-in window.
- Now you can select Certificates and right-click Trusted Root Certification Authorities on the MMC console window as below.
- Then you can click All Tasks > Import to open the Certificate Import Wizard window from which you can add the digital certificate to Windows.
If Microsoft Management Console can’t create a new document, follow the easy steps in this guide to solve the issue.
Now you’ve installed a new trusted root certificate in Windows 10. You can add many more digital certificates to that OS and other Windows platforms in a similar manner.
Just make sure that the third-party digital certificates come from trusted CAs, such as GoDaddy, DigiCert, Comodo, GlobalSign, Entrust and Symantec.
If you have any more suggestions or questions, leave them in the comments section below and we’ll certainly check them out.
RELATED STORIES YOU SHOULD CHECK OUT:
- Fix: “There is a problem connecting securely to this website” invalid certificate error
- Windows 10 removes security certificates from two Chinese companies
- 6 of the best website security software to use in 2019