From Android N (7.0) onwards it gets a littler harder, see this extract from the Charles proxy website: As of Android N, you need to add configuration to your app in order to

The two highest level CAs in the FPKI hierarchy are the FPKI Trust Infrastructure CAs, which are operated and managed by the Federal PKI Management Authority (FPKIMA) Program Office: COMMON serves as the root and trust anchor for the intermediate and issuing CAs operated by federal government Executive Branch agencies.

Prior to Android KitKat you have to root your device to install new certificates.

If you want to check the list of trusted roots on a particular Android device, you can do this through the Settings app.
Root Certificate Authority (CA) - Glossary | CSRC - NIST

Since 2012, all major browsers and certificate authorities participate in the CA/Browser Forum.

DigiCert Roots and Intermediates All active roots on this page are covered in our Certification Practice Statement (CPS). All certificates signed by the root certificate, with the "CA" field set to true, inherit the trustworthiness of the root certificatea signature by a root certificate is somewhat analogous to "notarizing" identity in the physical world.

The Federal PKI includes U.S. federal, state, local, tribal, territorial, and international governments, as well as commercial organizations, that work together to provide services for the benefit of the federal government.

That means those older versions of Android will no longer trust certificates issued by Lets Encrypt.". 

Root Certificate Authority (CA) Definition (s): In a hierarchical public key infrastructure (PKI), the certification authority (CA) whose public key serves as the most trusted datum (i.e., the beginning of trust paths) for a security domain.
PIV credentials and person identity certificates, PIV-Interoperable credentials and person identity certificates, A small number of federal enterprise device identity certificates, Identity certificates are issued and digitally signed by a, This process of issuing and signing continues until there is one, Facilities access, network authentication, and some application authentication for applications based on a risk assessment, Signed and encrypted email communications across federal agencies.

The ECA program is designed to provide the mechanism for these entities to securely communicate with the DoD and authenticate to DoD Information Systems.

These policies are determined through a formal voting process of browsers and CAs.
My next try was to install the certificate from SD card by copying it and using the according option from the settings menu.

I refreshed the PWA web app I had opened no my mobile Chrome (it is hosted on a local IIS Web Server) and voala!
Certificate-based authentication with federation - Azure Active

A root certificate is the top-most certificate of the tree, the private key which is used to "sign" other certificates.

See a graph of the Federal PKI, including the business communities.

The overarching policy of the Federal PKI is the Federal Common Policy Framework or the Federal Bridge Certificate Policy.

The set of https connections you will encounter breaks down into two disjoint subsets: For those you care about, you can click on the padlock icon in the address bar and see what CA is certifying this connection.

And, he adds, buying everyone a new phone isn't a realistic option.
ssl - android does not trust a certificate - Stack Overflow

Just pass the url to a .crt file to this function: The iframe trick works on Droids with API 19 and up, but older versions of the webview won't work like this.

Found a very detailed how-to guide on importing root certificates that actually steps you through installing trusted CA certificates on different versions of Android devices (among other devices).
The HTTPS-Only Standard - Certificates - CIO.GOV

All major CAs participate in CAA and promise to verify CAA DNS records before issuing certificates.

But such mis-issuance would be more likely to be detected with CAA in place.

A PIV certificate is a simple example.

In 2011, the Dutch certificate authority DigiNotar suffered a security breach.

Are there federal restrictions on acceptable certificate authorities to use?
PDF Government Root Certification Authority Certification Practice

Here's a function that works in just about any browser (or webview) to kickoff ca installation (generally through the shared os cert repository, including on a Droid).

Please check with your individual provider if they support your specific need.

The FCPCAs design enables any certificate issued by any FPKI CA to validate its certificate path to a single root CA.

Open Dory Certificate Android app, click the round [+] button and select the right Import File Certificate option.

In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA).

You can remove any CA certificate that you do not wish to trust.

View the webinar on-demand: Taming Certificate Sprawl, Digital trust solutions create new opportunities for Acmetek.

Maintainers of CA lists (Microsoft, Apple, Google, Mozilla, Oracle, etc) do not have the resources, legal authority, or inclination to audit the internal conduct of certificate authorities.

Though self-regulated, the CA/Browser Forum is effectively the governing body for publicly trusted certificate authorities.

Those you dont care about: most of the sites out there, where security is not an issue and they could just as easily use plain http for all you care.

An official website of the United States government.

Electronic passports are standardized modern security documents with many security features.

If you need your certificate for HTTPS connections you can add the .bks file as a raw resource to your application and extend DefaultHttpConnection so your certificates are used for HTTPS connections.

Issued to any type of device for authentication.

However, even when a publicly trusted commercial CA is cross-certified with the Federal PKI, they are expected to maintain complete separation between their publicly trusted certificates and their Federal PKI cross-certified certificates.

In Android (version 11), follow these steps: Open Settings Tap "Security" Tap "Encryption & credentials" Tap "Trusted credentials." This will display a list of all trusted certs on the device.

Installing new certificates as 'system trusted'-certificates requires more work (and requires root access), but it has the advantage of avoiding the Android lockscreen requirement.

FPKI Certification Authorities Overview.

Government Root Certification Authority Certification Practice Statement Version 1.4 Administrative Organization: National Development Council Executive Organization: ChungHwa Telecom Co., Ltd. May 20, 2014 .

I also saw that many certificates expire in 2037, shortly before the UNIX-rollover, presumably to avoid any currently unknown Y2K38-type bugs.
What Is a Root Certificate and How Can It Be Used to Spy on You? - MUO

There is one tell tail sign of MITM attacks on SSL: premature certificate changes with an unrelated CA.

The standard DNS is not secure, so CAA records could be suppressed or spoofed by an attacker in a privileged network position unless DNSSEC is in use by the domain owner and validated by each CA issuer.

Remember that, in any case, the point of the CA is to validate the certificate, which does not mean that the corresponding site is maintained by honest and trustworthy people; the only thing that the CA guarantees is that the Web page you are looking at really came from the Web site whose name is in the URL bar.

After two recent Slashdot articles (#1 #2) about questionable Root Certificates installed on machines, I decided to take a closer look at what I have installed on my machines.
Certificate Authorities Trusted by the Device

CA certificates (e.g. Is it worth the effort?

The government-issued certificate is called "Qaznet" and is described as a "national security certificate".

Microsoft distributes root certificates belonging to members of the Microsoft Root Certificate Program to Windows desktops and Windows Phone 8.

These CAs have established a trust relationship with the FPKI and are audited annually for conformance to the certificate policies.

Android stores CA certificates in its Java keystore in /system/etc/security/cacerts.bks.

There are many kinds of certificates in use in the federal government today, and the right one may depend on a systems technical architecture or an agencys business policies.

It is managed by the Identity Assurance and Trusted Access Division in the GSA Office of Government-wide Policy.

It is an hilarious, albeit sad comment about the CA ecosystem as it is right now.

I can of course build the new cacerts.bks, with root access I can even replace the old one, but it reverts to the original version with every reboot.

The trust lapse will hit about a third of the Android devices currently operating, Hoffman-Andrews claims.

Evil CA can trick your browser into thinking that you're securely connected to's server when you could be connected to another (DNS poisoning) and be looking at a fraudulent certificate.

This means that you can only use SSL Proxying with apps that you

Improved interoperability with other federal agencies and non-federal organizations that trust Federal PKI certificates.

However, users can now easily add their own 'user' certificates which will be stored in '/data/misc/keychain/certs-added'.

The server certificate was issued by the Intermediate CA "Go Daddy Secure Certificate Authority - G2" that was issued by the Root CA "Go Daddy Root Certificate Authority - G2".

This enables federal government systems to trust person and enterprise device certificates issued by FPKI CAs.

Did this satellite streak past the Hubble Space Telescope so close that it was out of focus?

Opened my cacerts.bks file from my sdcard (entered nothing when asked for a password).

You can specify The strength of Certificate Transparency increases as more CAs publish more certificates to public CT logs.

Administrators can configure the default set of trusted CAs and install their own private CA for verifying software.

Then how can I limit which CAs can issue certificates for a domain?

For normal computers which browse the internet and update dozens of applications in the background, just trust all of them and follow other security principles to protect your computer instead.

CA - L1E.

It doesn't solve the trust problem, but it does help detect discrepancies between certificates.

The CA/B Forum produces the Baseline Requirements (BRs), a set of technical and procedural policies that all CAs must adhere to.
How To Disable Root Certificates In Android 11 - ScreenRant

Devices use either the root store built in to its operating system, or a third-party root store via an application like a web browser.

Now, Android does not seem to reload the file automatically.

Before sharing sensitive information, make sure

But the plan is to maintain an option to set up an alternate link relation tied to the older DST Root X3 certificate for the sake of compatibility.

Yet, if one of the "default CA" begins to behave improperly, that's Apple public image which is at stake.

The https:// ensures that you are connecting to the official website and that any

Find centralized, trusted content and collaborate around the technologies you use most.

Is there a list for regular US users or a way to disable them and enable them when they ar needed?

If you are worried for any virus or alike, improve or get some good antivirus.
Trusted Root Certification Authorities Certificate Store

Phishing-Resistant Authenticators (Coming Soon), Federal Common Policy Certification Authority, All Federal PKI Certification Authorities, Federal Common and Federal Bridge Certificate Details, Federal PKI Management Authority (FPKIMA), Personal Identity Verification (PIV) credentials, PKI Shared Service Provider (SSP) Certification Authorities, An SSP CA operates under the Federal Common Certificate Policy and offer, Non-Federal Issuer (NFI) Certification Authorities, A Non-Federal Issuer or NFI is a private sector CA that is cross-certified with the Federal Bridge CA.

Let's Encrypt launched four years ago to make it easier to set up a secure website.

If you have a rooted device, you can use a Magisk Module to move User Certs to System so it will be Trusted Certificate,

What I did to beable to use startssl certificates was quite easy.

Microsoft also said in 2017 that they would remove the relevant certificates offline, but in February 2021 users still reported that certificates from WoSign and StartCom were still effective in Windows 10 and could only be removed manually.