Import Mozilla Root Certificates into Mono with mozroots

mozroots loads Mozilla's trusted root certificates into Mono's own certificate store, which is what lets Mono applications validate TLS at all. This build (Ubuntu's mono-devel 6.8.0.105+dfsg-3.6ubuntu2, importer version 6.8.0.105) also nags that mozroots is deprecated in favour of cert-sync. Allow about ten minutes for a first import, plus time to think through the trust decision.

Safety boundary: importing roots changes what TLS and other certificate checks will trust. A machine-store import affects every Mono user on the host. Do not reach for --sync until you have decided whether any roots outside Mozilla's list need to stay trusted.

1. Check the installed command

This is unprivileged and touches no certificate store:

$ command -v mozroots
/usr/bin/mozroots
$ mozroots --help
Unknown option '{0}'.
Mozilla Roots Importer - version 6.8.0.105
Download and import trusted root certificates from Mozilla's MXR.
WARNING: mozroots is deprecated, please move to cert-sync.

That first line is a quirk of this build: --help prints an option warning before the usage text. What matters is the executable path, the reported version and the deprecation notice. Read the full usage text if you need to confirm an option before scripting it.

2. Import into your user store

$ mozroots --import
Mozilla Roots Importer - version 6.8.0.105
Download and import trusted root certificates from Mozilla's MXR.
WARNING: mozroots is deprecated, please move to cert-sync.
Downloading from '...'
Importing certificates into user store...
Import process completed.

The URL and certificate count vary with the installed build and current source data; a first import can add roughly a hundred roots. If it asks you to confirm individual additions, only say yes to roots you have actually decided to trust, and hit Ctrl-C if a prompt looks unexpected.

Checkpoint: the output names the user store and ends with Import process completed. If it fails before that, do not reach for sudo out of habit; check the network error, proxy configuration and source URL first.

3. Choose confirmation or full sync deliberately

--sync makes the store match the downloaded Mozilla list exactly, adding and removing certificates as needed. Good for a fresh, empty Mono install or a controlled automated update. Bad news for a private or test root that Mozilla does not list, because sync will remove it:

$ mozroots --import --sync
Mozilla Roots Importer - version 6.8.0.105
Downloading from '...'
Importing certificates into user store...
... new root certificates were added to your trust store.
Import process completed.

There is no general undo in mozroots. Recovery means re-importing the certificate through Mono's own certificate-management tooling, or restoring the store from a backup you made before the sync. Do not use --sync as a routine repair without checking the store's contents first.

For an established store, three narrower flags let you keep control:

A first import with --ask or --ask-add can ask for many responses, so expect an interactive session, not a quiet batch job:

$ mozroots --import --ask-remove
... previously trusted certificates were not part of the update.
Are you sure you want to remove this certificate ? no

Answering no keeps that certificate for this run. Check the issuer and thumbprint in the prompt rather than deciding from a short or familiar-looking name.

4. Verify the result without changing it

$ ls -ld "$HOME/.config/.mono/certs"
$ find "$HOME/.config/.mono/certs" -maxdepth 1 -type f -printf '%f\n' | head
$ find "$HOME/.config/.mono/certs" -maxdepth 1 -type f | wc -l

Exact filenames and counts are implementation details, so treat this as a presence check, not an expected number. What matters is that an ordinary import writes only under your home directory. If you meant a user-only change and the machine directory changed instead, stop and investigate before running anything that depends on the store.

As a practical test, run the Mono application or test that originally complained about an untrusted root. A successful TLS connection shows a suitable trusted chain exists; it does not prove every certificate you wanted is present. Keep the original error and issuer details if the application still rejects the peer.

5. Touch the machine store only with a change plan

--machine targets the machine trust store instead of your own, and normally needs elevated privileges because that location is system-owned:

$ sudo mozroots --import --machine --ask-remove

Before running that, decide which Mono users and services should inherit the roots, record the current machine-store state, and arrange a maintenance window if applications will be affected. A failing application for one user is not, on its own, a reason for a machine-wide import.

Keep local enterprise roots in a separate, documented trust-management process. Mixing them with a Mozilla sync means a later --sync can remove them. Test the exact service account and trust-store location after any change, and keep a rollback copy or a documented re-import procedure.

6. Handle local source files and automation with care

--file NAME reads an LXR-format certificate-data file instead of downloading one, which can cut repeated downloads when several hosts share the same reviewed source:

$ mozroots --import --file /path/to/reviewed-certdata.txt --ask-remove

Only ever use a file whose origin and integrity you can vouch for. That file decides which roots get considered for import, so treating an untrusted download as a certificate policy is a security mistake, not a shortcut. --url URL works the same way for an alternative LXR source, and --quiet just quietens console output; neither makes an unattended trust change safe. Keep confirmation on until you understand the input, the destination store and the removal policy.

Never put a password or private key on the command line. mozroots only imports public root certificates: it will not turn a private certificate authority into a trusted one unless its public root goes through a supported certificate workflow.

Done means