AdGuard Certificate

AdguardTeam

Magisk
v2.1
Version
3.74 KB
Size
Jan 23, 2024
Updated

Module Info

  • Contributors sfionov, ngorskikh, ameshkov, grumaxxx, tonytkachenko
  • Source Code View Repository
  • Tags
    #AdGuard Certificate #AdGuard #HTTPS Filtering #CA Certificate #System Trust Store #Magisk Module

About this module

AdGuard Certificate supplements AdGuard for Android on rooted devices by placing the generated AdGuard certificate in the system trust store, allowing HTTPS filtering to cover applications that do not trust user-installed certificates.

System Trust for AdGuard Filtering

Bridge Android's user and system certificate stores while retaining a validation path suitable for Chromium-based browsers.

System Store Placement

Moves the appropriate AdGuard CA into Android's system certificate store for applications that reject user certificates.

Cross-Signed Pair

Works with the two certificates generated by current AdGuard versions so browsers can use the user-store path without requiring Certificate Transparency logs.

Boot-Time Synchronization

Copies the certificate during boot, so a restart is required whenever AdGuard replaces or regenerates its certificate.

Why AdGuard Uses Two Certificates

Many Android applications do not trust certificate authorities installed only by the user. Moving AdGuard's CA into the system store lets those applications build a trust chain for AdGuard's HTTPS filtering, but Chromium-based browsers apply Certificate Transparency requirements to system roots.

For rooted devices, current AdGuard versions generate a pair of related certificates. The module places one certificate in the system store and leaves the cross-signed certificate in the user store. Applications that require a system root can use the first path, while browsers that accept user certificates can build the shorter user-store path without treating the AdGuard CA as a conventional system root that needs public CT logs.

Setup

  1. Enable HTTPS filtering in AdGuard for Android and save the generated certificates to the user store.
  2. Install the module ZIP through Magisk.
  3. Restart Android so the required certificate is copied into the system store.

Boot-Time Certificate Handling

At startup, the module looks for the most recently installed AdGuard Personal CA in Android's user certificate directories. It copies that certificate under the system-trust filename expected by Android and removes matching disabled-certificate markers that would otherwise cause applications to reject it.

On devices using the Mainline Conscrypt certificate store, including modern Android releases, the module prepares a temporary copy of the APEX trust directory, adds the AdGuard certificate, fixes ownership and SELinux context, and bind-mounts the result into the required process namespaces. This is why installing or regenerating the certificate requires a reboot.

Certificate changes: If AdGuard creates a new CA, restart the device so the module can select and install the new certificate. Updating the module itself also follows the normal Magisk installation and reboot cycle.
Version and trust implicationsVersion 2.x is designed for AdGuard for Android 4.2 and newer; AdGuard 4.1 or earlier requires module version 1.2. A system-trusted filtering CA can inspect encrypted traffic handled by AdGuard, so use the module only on a device you administer and protect the associated certificate material.