Custom Certificate Authorities copies CA certificates installed in Android's user credential store into system-trusted locations during boot. It handles Android 14+'s Conscrypt APEX store, the legacy system path used by BoringSSL-based apps, automatic DER-to-PEM conversion, and certificates belonging to multiple Android users.
Promote User CAs to System Trust
Install and remove certificates through Android Settings; the module synchronizes the systemless trust-store mounts after reboot.
User Store Input
Reads CAs installed through the normal Android credential interface, avoiding manual hash naming for the common workflow.
DER-to-PEM Conversion
Converts binary DER certificates to PEM where needed so BoringSSL consumers such as Flutter and Dart apps can parse them.
Dual Trust Paths
Bind-mounts certificates into the Conscrypt APEX path and /system/etc/security/cacerts on Android 14 and newer.
Certificate Workflow
- Use Android 11 or newer with Magisk 24.1 or newer.
- Install the module through Magisk and reboot if the manager requests it.
- Open Settings → Security → Encryption & credentials → Install a certificate → CA certificate and install the required CA.
- Reboot so the module can copy and mount the certificate into the system trust stores.
To remove trust, delete the CA from the User tab under Trusted credentials and reboot. The next synchronization omits it from the module's system-store view.
Verification and Limitations
Inspect the module log after reboot:
adb shell su -c 'cat /data/local/tmp/customcert.log'The certificate should also appear in the System tab of Android's Trusted credentials screen. If it does not, confirm that the CA was installed in Android Settings and that the module is enabled.
System trust does not override certificate pinning, a private trust manager, mutual-TLS requirements, or an application that bundles its own CA set. Those applications can continue rejecting the certificate even when Android lists it as system-trusted.