Automatically trust third-party root certificates in Waterfox
On Windows and macOS, Waterfox can automatically trust third-party root certificates installed in the operating system’s certificate store. This can be useful on managed networks and with security software that uses a locally installed certificate authority.
What are third-party root certificates?
Root certificates identify certificate authorities that Waterfox trusts to verify secure HTTPS connections. Waterfox includes a built-in set of trusted roots. Your operating system, an administrator or installed software can add other roots to the system certificate store. These are third-party root certificates from Waterfox’s perspective.
How automatic trust works
When the setting is enabled, Waterfox imports supported root certificates from the operating system and can use them when it verifies a website’s certificate chain. This avoids separate certificate configuration in Waterfox for many managed environments.
Caution
Only install root certificates from sources you trust. A trusted root can issue certificates that Waterfox accepts for secure sites, so an unwanted root could allow encrypted traffic to be intercepted. Contact your administrator before changing this setting on a managed device.
Manage the setting
This setting is enabled by default on supported systems.
- Click the menu button and select Settings.
- Select Privacy & Security.
- Under Connection and software security, select Advanced settings.
- Under Certificates, clear Allow Waterfox to automatically trust third-party root certificates you install.
If an enterprise policy manages certificates, the option may be hidden or locked.
Copyright and Licensing
Adapted for Waterfox from the original Firefox article Automatically trust third-party root certificates in Firefox. Original content by Mozilla Contributors. Licensed under the CC BY-SA 3.0.