AdGuard Certificate supplements AdGuard for Android on rooted devices by placing the generated AdGuard certificate in the system trust store, allowing HTTPS filtering to cover applications that do not trust user-installed certificates.
System Trust for AdGuard Filtering
Bridge Android's user and system certificate stores while retaining a validation path suitable for Chromium-based browsers.
System Store Placement
Moves the appropriate AdGuard CA into Android's system certificate store for applications that reject user certificates.
Cross-Signed Pair
Works with the two certificates generated by current AdGuard versions so browsers can use the user-store path without requiring Certificate Transparency logs.
Boot-Time Synchronization
Copies the certificate during boot, so a restart is required whenever AdGuard replaces or regenerates its certificate.
Why AdGuard Uses Two Certificates
Many Android applications do not trust certificate authorities installed only by the user. Moving AdGuard's CA into the system store lets those applications build a trust chain for AdGuard's HTTPS filtering, but Chromium-based browsers apply Certificate Transparency requirements to system roots.
For rooted devices, current AdGuard versions generate a pair of related certificates. The module places one certificate in the system store and leaves the cross-signed certificate in the user store. Applications that require a system root can use the first path, while browsers that accept user certificates can build the shorter user-store path without treating the AdGuard CA as a conventional system root that needs public CT logs.
Setup
- Enable HTTPS filtering in AdGuard for Android and save the generated certificates to the user store.
- Install the module ZIP through Magisk.
- Restart Android so the required certificate is copied into the system store.
Boot-Time Certificate Handling
At startup, the module looks for the most recently installed AdGuard Personal CA in Android's user certificate directories. It copies that certificate under the system-trust filename expected by Android and removes matching disabled-certificate markers that would otherwise cause applications to reject it.
On devices using the Mainline Conscrypt certificate store, including modern Android releases, the module prepares a temporary copy of the APEX trust directory, adds the AdGuard certificate, fixes ownership and SELinux context, and bind-mounts the result into the required process namespaces. This is why installing or regenerating the certificate requires a reboot.