Always Trust User Certs

Jeroen Beckers (NVISO.eu)

Magisk KernelSU
v1.3
Version
6.65 KB
Size
May 21, 2025
Updated

Module Info

  • Contributors TheDauntless, enovella, Crystalix007, T3rm1
  • Source Code View Repository
  • Tags
    #Always Trust User Certs #CA Certificate #System Trust Store #Conscrypt #HTTPS Inspection #Magisk Module #KernelSU #Security Testing

About this module

Always Trust User Certs copies user-installed certificate authorities into Android's system trust store, allowing applications to include those certificates when building trust chains without requiring an app-specific network security configuration.

Synchronize User CAs with System Trust

Support controlled HTTPS inspection and development workflows across Android's legacy and Mainline certificate-store layouts.

Automatic Promotion

Copies certificates from the user store into the appropriate system root CA location during startup.

Legacy and Conscrypt Paths

Handles both /system/etc/security/cacerts and Mainline Conscrypt storage under /apex/com.android.conscrypt/cacerts.

Multiple Users

Includes official support for certificates installed under Android configurations with multiple users or profiles.

How Certificate Synchronization Works

During the early boot phase, the module scans the certificate directories for every Android user and copies each user-added CA into its system certificate overlay. Before rebuilding that overlay, it clears the previous copied set, ensuring that a certificate removed from Android Settings is not silently retained as a system-trusted root after the next restart.

The module also merges Android's existing system roots so the resulting store contains both the platform certificates and the promoted user certificates. On devices that use the Mainline Conscrypt APEX, its service waits for boot completion, prepares the merged store with the required ownership and SELinux labels, and mounts it into the zygote and application process namespaces.

Usage

Install a Certificate

Add the CA through Android Settings as a user certificate, then restart the device so the module can copy it into the system store.

Remove a Certificate

Delete the CA from the user store and restart. The module refreshes its system overlay so removed user certificates are no longer retained.

Compatibility

The upstream project documents Android 7 through Android 16 and supports Magisk, KernelSU, and KernelSU Next. It handles devices both with and without Mainline or Conscrypt certificate-store updates, selecting the legacy /system/etc/security/cacerts path or the modern /apex/com.android.conscrypt/cacerts layout as needed.

Applications can still implement certificate pinning or a custom trust manager that ignores the platform root store. Promoting a CA to the system store changes Android's normal trust-chain construction, but it does not guarantee interception of every application.