What importing to Trusted Root means and when you need to do it

Importing a certificate into Windows Trusted Root Certification Authorities tells your computer to trust that certificate and any others signed by it. When you import a root certificate, Windows stops warning you about websites, software, or encrypted connections that use certificates from that authority. This is useful when you work with internal company systems, test environments, or specialized software that uses its own certificate authority instead of a public one like DigiCert or Let's Encrypt.

The process itself is straightforward: you obtain a certificate file, open Windows Certificate Manager, and move the file into the Trusted Root folder. However, importing the wrong certificate or importing one without understanding what it does can create security gaps. Only import certificates you trust completely, because once in Trusted Root, that certificate can validate any other certificate it has signed.

Key Takeaways

  • You need the certificate file itself, usually named with a .cer, .crt, or .pem extension, before you can import it.
  • Windows Certificate Manager is the built-in tool for importing; you access it by typing "certmgr.msc" into the Run dialog or searching for it in Settings.
  • Certificates go into the Trusted Root Certification Authorities store, and once there, Windows treats any certificate signed by that root as trustworthy.
  • Only administrators can import certificates into Trusted Root; if you do not have admin rights, the import will fail or require a password.
  • Importing a certificate affects your entire Windows user account or the whole computer, depending on whether you import it to your user store or the system store.

Getting the certificate file you need

Before you can import anything, you need the actual certificate file. This usually comes from your IT department, your company's internal systems, or the organization that runs the certificate authority you want to trust. The file will have an extension like .cer, .crt, .pem, or sometimes .p7b.

Ask whoever gave you the certificate what it is for and confirm it is a root certificate, not an intermediate or end-entity certificate. A root certificate is the top of the chain and is what you import to Trusted Root. If you import an intermediate certificate by mistake, it may not work as expected. If you are unsure, ask before importing — importing the wrong certificate is easier than removing it later.

Save the certificate file somewhere you can find it, like your Desktop or Documents folder. You will need to browse to it during the import process.

Opening Windows Certificate Manager

The easiest way to open Certificate Manager is to use the Run dialog. Press Windows key + R, type certmgr.msc, and press Enter. A window titled "Certificate Manager" will open.

If the Run dialog does not work on your computer, you can search for Certificate Manager in the Windows search box instead. Click the Windows icon in the bottom left, type "certificate manager", and click the result that says "Manage user certificates".

You may see a prompt asking for administrator permission. Click Yes to continue. If you do not have administrator rights on your computer, you will not be able to import into Trusted Root — you will need to contact your IT department or the person who manages your computer.

Navigating to Trusted Root Certification Authorities

Once Certificate Manager is open, look at the left panel. You will see a folder tree starting with "Certificates — Current User". Click the arrow or plus sign next to it to expand the list. You should see several folders, including one called Trusted Root Certification Authorities.

Click on Trusted Root Certification Authorities to select it. The right panel will show any certificates already in that store. This is where your new certificate will go once you import it.

Do not click on the subfolders like "Certificates" or "CRLs" — stay at the main Trusted Root Certification Authorities level.

Importing the certificate file

With Trusted Root Certification Authorities selected, right-click on it and choose Import from the menu. A wizard window will open titled "Certificate Import Wizard".

Click Next on the first screen. On the second screen, you will see a field asking for the filename. Click Browse, navigate to where you saved your certificate file, select it, and click Open. The filename will appear in the field. Click Next again.

The wizard will ask which certificate store to use. Make sure Trusted Root Certification Authorities is selected in the dropdown. If it is not, click the dropdown and select it. Click Next.

Review the summary screen to confirm the certificate details and the destination store. If everything looks correct, click Finish. A small dialog will appear saying "The import was successful". Click OK.

Verifying the certificate was imported

After the import completes, you should see your certificate listed in the right panel of Certificate Manager under Trusted Root Certification Authorities. Look for the certificate name or subject — it should match the certificate file you imported. If you do not see it, the import may have failed; try the process again and watch for any error messages.

You can double-click the certificate to view its details and confirm it is the right one. The Details tab will show the certificate subject, issuer, and expiration date. Close this window when you are done.

Once the certificate is in Trusted Root, Windows will recognize it the next time you encounter a connection or document signed by that certificate authority. You may need to restart applications or refresh web pages for the change to take effect.

Removing a certificate if you imported the wrong one

If you imported a certificate by mistake, you can remove it. Open Certificate Manager again, navigate to Trusted Root Certification Authorities, find the certificate you want to remove, right-click it, and choose Delete. Confirm the deletion when prompted.

After removing a certificate, Windows will go back to warning you about connections or documents signed by that authority, or it will reject them entirely depending on the context. If you need that certificate again, you can import it once more.

Frequently Asked Questions

What is the difference between importing to my user store and the system store?

When you import through Certificate Manager (certmgr.msc), the certificate goes into your user store and only affects your account. If you want the certificate to apply to all users on the computer, you need to import it to the system store instead, which requires opening Certificate Manager for the local computer. This is less common and usually only done by IT administrators.

Can I import a certificate that is already expired?

Windows will let you import an expired certificate, but it will not work for validating new connections or documents. Expired certificates are only useful if you need to verify something that was signed before the certificate expired. If you are importing a certificate for ongoing use, make sure it has not expired yet.

What happens if I import a certificate I should not trust?

Any certificate signed by a root certificate in your Trusted Root store will be accepted by Windows as trustworthy. If someone has access to a private key for a certificate in your Trusted Root store, they could create fraudulent certificates that your computer would accept. Only import certificates from sources you trust completely, and remove any certificate you no longer need.

Do I need to restart my computer after importing a certificate?

Most applications will recognize the new certificate without a restart, but some may need to be closed and reopened. Web browsers usually pick up the change immediately. If an application still does not recognize the certificate after importing it, try closing and reopening that application first before restarting your computer.

Where can I get the certificate file if my IT department did not give me one?

Contact your IT department or the organization that runs the system you are trying to access. They can export the root certificate and send it to you. If you are setting up a test environment or internal system yourself, you will need to generate the certificate using a tool like OpenSSL or a certificate management utility, then export it in a format like .cer or .pem before importing it into Windows.