Root CA Certificates
When you visit a service on the network (and on the internet), your browser needs to identify that the site is who it says it is.
September 30, 2026
Installing the doxx.net root CA certificate does this by identifying that the domain certificate from the service you are trying to reach is real.
This isn't automatically covered by installing the app or connecting a WireGuard tunnel.
If you don’t have the root CA certificate installed you will have to ignore the unsafe website warning popup that your browser will display when you reach the service.
1.Features
- Give a device or application a trusted reference for checking certificates issued by doxx.net's private authority.
- Use the official installation instructions for the platform you're setting up.
- Keep certificate trust separate from connecting a tunnel or opening a firewall rule.
To install the Root CA Certificate online visit on the doxx.net portal DNS and PKI → Install Root CA and follow the steps in the portal.
Or on the App: Account → Settings ⚙ → Privacy → Web Privacy and follow the steps in the app
2.Common Questions
Is the root CA certificate the same as my service's certificate?
No. The root identifies the certificate authority you trust. Your service presents its own domain certificate, which is checked against that trust.
Should I click through a certificate warning?
Don't bypass it as the normal setup method. Follow the official root-installation steps and check that the certificate matches the domain and is valid. If you can't explain the warning, stop and ask for help.
Does installing the root certificate connect me to the network?
No. Certificate trust, DNS resolution and network access are separate. You may still need to connect to doxx.net and have permission to reach the service.
Can I install any root certificate someone sends me?
Only install a root certificate from an authority you intend to trust, using its official source. Adding a root changes which certificates your device or application will accept.
Is this the same as installing my domain certificate on the server?
No. The server uses its domain certificate and private key. The connecting device needs to trust the issuer. Those are two different parts of the setup.