Default Horse internal CA

This installs trust for the private certificate authority used by services under on.default.horse and home.arpa on this tailnet. It does not grant trust for anything else.

iOS / iPadOS
  1. Download the profile and open it.
  2. Settings → General → VPN & Device Management, tap the profile, Install.
  3. Settings → General → About → Certificate Trust Settings, enable full trust for “Default Horse CA”. This step is required — installing the profile alone isn't enough.
macOS

Either works:

Windows

Either works:

Android
  1. Download the certificate.
  2. Settings → Security & privacy → More security & privacy → Encryption & credentials → Install a certificate → CA certificate (exact wording and path vary by manufacturer/Android version), then select the downloaded file and confirm the warning.

Note: Android doesn't trust user-installed CAs for most apps by default on Android 7+ (only for apps that explicitly opt in via their network security config) — this will work for browsers like Chrome/Firefox, but individual apps may still reject it.

Linux / other (step CLI)

Fetches the root over TLS, verifies it against the fingerprint, and installs it into your system trust store in one step:

step ca bootstrap \
  --ca-url https://100.64.0.1:8443 \
  --fingerprint 8da5e76689f38d91ee850f841b52f1bf8a5d74f1a250ce7c2d9bf5ccddf088f9 \
  --install