- Key Takeaways
- Why do Different Platforms Maintain Separate Trust Stores?
- How does a CA get its Root Certificate Added to a Trust Store?
- What happens when a root is removed from a trust store?
- Can an Organization add its Own Root CA to a Trust Store?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Deploy Certificates That Are Trusted Exactly Where You Need Them
Trust Stores are a repository of root Certificate Authority certificates that an operating system, browser, or application treats as inherently trustworthy, forming the starting point every certificate chain must trace back to before it is accepted.
A trust store holds the set of root CA certificates a device or application trusts by default. When validating a TLS certificate, software checks whether the certificate chains up to a root already in its trust store; if it does, and every signature and validity check passes, the connection is trusted, otherwise it is rejected.
Key Takeaways
- Major platforms, including Microsoft, Apple, Google, and Mozilla, each maintain their own independent root store with its own inclusion and removal policies.
- A CA must pass a rigorous, often multi-year audit process to have its root certificate included in a major trust store, since inclusion grants it the ability to be trusted globally.
- Trust stores can and do remove roots: Symantec-issued roots were distrusted by major browsers in 2018 following mis-issuance findings, requiring affected sites to switch CAs.
- Enterprises can add their own internal root CA to managed devices’ trust stores, letting internally issued certificates be trusted without needing public CA validation.
- A certificate chaining to a root not present in the relying party’s trust store fails validation regardless of how correctly it was otherwise issued.
Why do Different Platforms Maintain Separate Trust Stores?
Microsoft, Apple, Google (Chrome), and Mozilla (Firefox) each run independent root programs with their own audit requirements, inclusion criteria, and removal processes. This means a CA’s root certificate could be trusted in one browser’s store but not yet in another’s, and it is why organizations sometimes see certificate warnings on one platform but not another during a CA’s inclusion rollout or removal process.
How does a CA get its Root Certificate Added to a Trust Store?
- The CA submits an application to the root program (e.g., Microsoft, Apple, Mozilla, Chrome Root Program) along with its Certificate Practice Statement.
- An independent auditor evaluates the CA’s operational, security, and issuance practices against the program’s requirements.
- The root program reviews the audit results and any public comment period feedback.
- If approved, the root certificate is distributed to the platform’s users, typically through an operating system or browser update.
- The CA must continue passing annual audits to remain included; failing to do so can result in removal.
What happens when a root is removed from a trust store?
When a root is distrusted, every certificate chaining to it stops being trusted by that platform, even if those individual certificates were validly issued. This happened in 2018 when major browsers distrusted Symantec-issued roots following findings of improper validation practices, forcing every site using a Symantec-chain certificate to migrate to a different CA before the distrust date or show certificate errors to visitors.
Can an Organization add its Own Root CA to a Trust Store?
Yes. Enterprises commonly deploy an internal root CA and push it to managed devices’ trust stores via Group Policy, mobile device management, or similar tooling. This lets internally issued certificates, for example for internal applications or VPN authentication, be trusted by company devices without requiring a public CA to validate and issue them, at the cost of that root only being trusted on devices where it has been explicitly installed.
How Encryption Consulting Helps
How Encryption Consulting HelpsPKI-as-a-Service designs and operates internal root and issuing CA hierarchies, including deployment of internal roots to managed device trust stores, so enterprise-issued certificates are trusted exactly where they need to be. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
What is the difference between a trust store and a Certificate Authority?
A Certificate Authority issues and signs certificates. A trust store is the repository, held by an operating system, browser, or application, of which root CA certificates it treats as trustworthy. A CA’s certificates are only automatically trusted on platforms whose trust store includes that CA’s root.
Why did some websites show certificate errors after Symantec’s roots were distrusted?
In 2018, major browsers removed trust in Symantec-issued roots following mis-issuance findings. Any site still using a certificate chaining to one of those roots after the distrust date showed a certificate error until it switched to a certificate from a different, still-trusted CA.
Can I add a custom root CA to my company’s devices?
Yes. Organizations commonly deploy an internal root CA and distribute it to managed devices via Group Policy or mobile device management tools, allowing internally issued certificates to be trusted on those devices without needing public CA issuance.
How does a browser decide whether to trust a certificate?
A browser checks whether the presented certificate chains, through zero or more intermediate CAs, up to a root certificate already present in its trust store. If that chain validates, and every certificate in it is unexpired and unrevoked, the browser trusts the connection.
Deploy Certificates That Are Trusted Exactly Where You Need Them
Take the next step PKI-as-a-Service designs internal CA hierarchies and manages trust store deployment across your device fleet. Explore PKI-as-a-Service to get started.
- Key Takeaways
- Why do Different Platforms Maintain Separate Trust Stores?
- How does a CA get its Root Certificate Added to a Trust Store?
- What happens when a root is removed from a trust store?
- Can an Organization add its Own Root CA to a Trust Store?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Deploy Certificates That Are Trusted Exactly Where You Need Them
