SSL Toolkit Logo

CA Trust Store

Verify CA trust store and root certificate status

About

The CA Trust Store Lookup tool checks which root Certificate Authorities are trusted by major browsers and operating systems. It provides a comprehensive view of CA trust status across different platforms including Mozilla Firefox, Apple macOS/iOS, Microsoft Windows, and Android/Chrome. This helps you understand whether certificates issued by a specific CA will be trusted by your users across all platforms.

The tool also tracks CA trust store changes, including newly added CAs, removed CAs, and CAs with restricted trust. With the rise of distrust events (like Symantec, CNNIC, and StartCom), knowing which CAs are trusted by which platforms is critical for maintaining universal compatibility. Use this tool when evaluating a new CA or troubleshooting trust issues on specific platforms.

How to Use

  1. 1Enter a domain name to check which CA issued its certificate and verify trust status
  2. 2Or browse the full trust store to see all trusted CAs across platforms
  3. 3Filter by platform (Mozilla, Apple, Microsoft, Google) to see platform-specific trust status
  4. 4Review the detailed trust information including certificate fingerprints and trust constraints

Use Cases

  • CA Evaluation: Before choosing a Certificate Authority, verify their root certificates are trusted by all major platforms your users operate on
  • Distrust Event Monitoring: Stay informed when CAs are distrusted by browsers (like Symantec, WoSign) and identify affected certificates
  • Cross-Platform Compatibility: Ensure certificates issued by your CA will be trusted on Windows, macOS, iOS, Android, and Linux systems
  • Enterprise Trust Management: Manage custom trust stores for enterprise environments where standard trust stores are modified
  • Compliance Documentation: Generate reports showing CA trust status for security audits and compliance requirements

Tips & Best Practices

  • Always verify CA trust across all platforms before deploying certificates in production
  • Monitor CA distrust announcements and check your certificates against the updated trust stores
  • When using private or internal CAs, ensure they are added to all endpoint trust stores
  • Consider using CAs with cross-signed roots for maximum compatibility across older and newer platforms

Technical Details

Trust Stores: Maintains up-to-date trust stores from Mozilla NSS, Apple Security, Microsoft Root Program, and Google Chrome
Distrust Tracking: Records historical distrust events with dates, reasons, and affected certificate ranges
Cross-Signing: Identifies cross-signed certificates and their trust paths through multiple root CAs
Constraint Analysis: Reports nameConstraints, pathLenConstraints, and other trust-limiting extensions

Frequently Asked Questions

Different browser and OS vendors maintain their own root certificate trust stores and have different policies for adding, removing, or restricting CAs. A certificate issued by a CA trusted by Mozilla but not yet approved by Microsoft will work in Firefox but show trust errors in Edge/IE. This is why checking cross-platform trust is essential.
Trust store updates happen frequently — Mozilla updates monthly, Apple and Microsoft quarterly, and Google with Chrome releases. Major changes like CA distrust events can happen suddenly. Our tool tracks these changes and alerts you when certificates from CAs you use are affected.
If your CA is distrusted on a platform, you need to replace certificates with one from a trusted CA before the distrust takes effect. Most distrust events have a grace period. Plan migration to an alternative CA immediately and test certificate deployment across all affected platforms.