Always Trust User Certs copies user-installed certificate authorities into Android's system trust store, allowing applications to include those certificates when building trust chains without requiring an app-specific network security configuration.
Synchronize User CAs with System Trust
Support controlled HTTPS inspection and development workflows across Android's legacy and Mainline certificate-store layouts.
Automatic Promotion
Copies certificates from the user store into the appropriate system root CA location during startup.
Legacy and Conscrypt Paths
Handles both /system/etc/security/cacerts and Mainline Conscrypt storage under /apex/com.android.conscrypt/cacerts.
Multiple Users
Includes official support for certificates installed under Android configurations with multiple users or profiles.
How Certificate Synchronization Works
During the early boot phase, the module scans the certificate directories for every Android user and copies each user-added CA into its system certificate overlay. Before rebuilding that overlay, it clears the previous copied set, ensuring that a certificate removed from Android Settings is not silently retained as a system-trusted root after the next restart.
The module also merges Android's existing system roots so the resulting store contains both the platform certificates and the promoted user certificates. On devices that use the Mainline Conscrypt APEX, its service waits for boot completion, prepares the merged store with the required ownership and SELinux labels, and mounts it into the zygote and application process namespaces.
Usage
Install a Certificate
Add the CA through Android Settings as a user certificate, then restart the device so the module can copy it into the system store.
Remove a Certificate
Delete the CA from the user store and restart. The module refreshes its system overlay so removed user certificates are no longer retained.
Compatibility
The upstream project documents Android 7 through Android 16 and supports Magisk, KernelSU, and KernelSU Next. It handles devices both with and without Mainline or Conscrypt certificate-store updates, selecting the legacy /system/etc/security/cacerts path or the modern /apex/com.android.conscrypt/cacerts layout as needed.
Applications can still implement certificate pinning or a custom trust manager that ignores the platform root store. Promoting a CA to the system store changes Android's normal trust-chain construction, but it does not guarantee interception of every application.