iOS: the profile is installed but the certificate is not trusted

On iOS a root certificate takes two steps, not one. The second one is hidden under About, and nothing works without it.

What it means

The profile is installed, but Safari still says the connection is not private and the proxy stays empty. On iOS a root certificate takes two steps: install it, then trust it. Apple split those steps in iOS 10.3. Until you turn trust on by hand, the certificate does nothing.

How to fix it

Set the proxy in the Wi-Fi settings first. A separate page covers that.

Step 1. Install the profile.

Open the certificate URL in Safari. Other iOS browsers just save the file; Settings never offers to install it.

Safari asks whether to allow the download. Allow it. Then: Settings → «Profile Downloaded» (near the top, under your account details) → Install → passcode → Install again → Done.

Two limits here. A downloaded profile is deleted after 8 minutes if you do not install it, and only one profile can be pending at a time. If the row is gone, download the certificate again.

Step 2. Turn on full trust. This is the step people miss.

Settings → General → About → scroll to the bottom → Certificate Trust Settings → turn on the switch next to your certificate, under «Enable full trust for root certificates». iOS warns that this lets the certificate's owner read your traffic. The warning is correct. The owner is you.

Step 3. Check. Open any https site in Safari. No warning, and requests appearing in the proxy, means you are done.

Special cases

Before step 2 the profile says «Not Verified». That red line under Settings → General → VPN & Device Management → your profile is normal. It turns to «Verified» once full trust is on.

There is no switch to turn on. Two reasons. The certificate is not a root CA, so it has to be self-signed and carry basicConstraints with cA set (RFC 5280 § 4.2.1.9). Or it was installed by MDM or Apple Configurator: those are trusted on install and never get a switch.

A managed phone. An MDM administrator can block profile installation entirely. Then step 1 fails and there is nothing to trust.

The simulator. One command, no tapping:

xcrun simctl keychain booted add-root-cert /path/to/ca.cer

That writes the certificate straight into the simulator's trust store, so step 2 is not needed. Dragging the .cer onto the simulator window also works, but then you still have to do step 2 inside the simulator.

An app that pins. System trust means nothing to it. An app that checks the certificate itself will refuse the connection. Only a code change fixes that.

App Transport Security. NSAllowsArbitraryLoads is a popular answer and a wrong one. ATS accepts a root certificate the user has given full trust to. Do not disable ATS for a proxy: in a release build you will have to justify it to App Review.

A wrong clock. A certificate is only valid for a fixed window (RFC 5280 § 4.1.2.5). If the phone's date is off, iOS reads the certificate as expired and refuses it even with trust on. Settings → General → Date & Time → Set Automatically.

An old certificate from another proxy. Two root certificates are in the store and the phone may pick the wrong one. Remove the extra one: Settings → General → VPN & Device Management → the profile → Remove Profile.

See it on your own traffic

After step 2 the phone's requests arrive in full: host, path, headers, bodies. Before it you see only connections to port 443 that open and die: the app started the TLS handshake, rejected the certificate and left. Full setup steps: Mobile Devices.

View in Solpuga

Related