This installs trust for the private certificate authority used by
services under on.default.horse and home.arpa
on this tailnet. It does not grant trust for anything else.
Either works:
step installed:
step ca bootstrap \
--ca-url https://100.64.0.1:8443 \
--fingerprint 8da5e76689f38d91ee850f841b52f1bf8a5d74f1a250ce7c2d9bf5ccddf088f9 \
--install
Either works:
certutil -addstore -f "Root" default-horse-root-ca.crt
step installed, same command as macOS/Linux
below — --install uses certutil under
the hood on Windows too.Note: Android doesn't trust user-installed CAs for most apps by default on Android 7+ (only for apps that explicitly opt in via their network security config) — this will work for browsers like Chrome/Firefox, but individual apps may still reject it.
Fetches the root over TLS, verifies it against the fingerprint, and installs it into your system trust store in one step:
step ca bootstrap \
--ca-url https://100.64.0.1:8443 \
--fingerprint 8da5e76689f38d91ee850f841b52f1bf8a5d74f1a250ce7c2d9bf5ccddf088f9 \
--install