Toggle Mono's Test Root Trust Safely with setreg
You will inspect Mono's public-key cryptography setting, enable or disable trust for Mono and Microsoft test root certificates, and verify the result for the current user. The examples use setreg from mono-devel version 6.8.0.105+dfsg-3.6ubuntu2, whose program reports Mono Set Registry version 6.8.0.105.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell and the Mono development tools package. The normal command is unprivileged: setreg changes the current user's trust store, not a machine-wide setting. Do not add sudo unless your own account cannot access its Mono configuration, and do not use a production trust store for the first test.
1. Check the installed command
Confirm which executable is on your path and record the package version. These are read-only checks:
$ command -v setreg
/usr/bin/setreg
$ dpkg-query -W -f='${Package} ${Version}\n' mono-devel
mono-devel 6.8.0.105+dfsg-3.6ubuntu2
$ setreg -help
The installed help option is documented as -help, with -h, -? and /? also accepted. The program's banner identifies the setting as Trusting Test Roots (Mono and Microsoft). The manual describes the command shape as setreg [options] [feature] [true|false].
Checkpoint: if command -v finds a different binary, stop and inspect that installation before changing a setting. Version-specific output belongs to the executable you actually ran.
2. Inspect the current setting
Run setreg without a feature or value. It prints the current configuration and does not request a change:
$ setreg
Mono Set Registry - version 6.8.0.105
Change settings for public key cryptography
Current configuration
1 Trusting Test Roots (Mono and Microsoft) FALSE
On this installation, the command exits with status 0 and reports FALSE initially. Your result may be TRUE if another process or an earlier test has changed the current user's setting. The important value is the row for feature 1, not the banner wording.
The manpage calls feature 1 a trust-store operation. Setting it to TRUE adds two self-signed test certificates, one associated with Microsoft and one with Mono, to the current user's trust store. Setting it to FALSE removes them. This is security-sensitive: a certificate signed by one of those test roots can be accepted as trusted by Mono applications for that user.
3. Enable test-root trust only for a controlled test
Before changing state, make sure the application you are testing really requires Mono's test roots. Never enable this setting as a general workaround for a broken certificate chain, and do not use it to make an unknown production endpoint appear trustworthy.
When the test is authorised, enable feature 1:
$ setreg 1 true
$ printf 'setreg status: %s\n' "$?"
setreg status: 0
The command's status 0 means the operation completed for the current user. It does not prove that every Mono process has reloaded its certificate state. Restart the test application if its certificate store is cached.
Checkpoint: immediately inspect the row again:
$ setreg
Current configuration
1 Trusting Test Roots (Mono and Microsoft) TRUE
The header and surrounding wording can vary with the installed build. Confirm that feature 1 is shown as TRUE. Do not assume that a silent command, or a zero exit status alone, proves the intended policy without this check.
4. Revoke the setting when the test ends
Leaving test roots trusted widens certificate acceptance beyond the normal trust anchors. Treat the change like a temporary debugging switch and undo it as soon as the test no longer needs it:
$ setreg 1 false
$ setreg
Current configuration
1 Trusting Test Roots (Mono and Microsoft) FALSE
This is the recovery command for the change made above. It removes the two test roots from the current user's trust store. If the setting was already TRUE before your work, do not blindly restore FALSE: record the initial value first and restore that value instead.
There is no service restart in this workflow. However, an already-running process may retain certificate objects or cached validation decisions. Stop and restart the test process according to its normal operating procedure, then inspect the setting again. Do not restart an unrelated production service merely because setreg completed.
5. Exercise the command without touching your real account
For a first run, use a temporary home directory. This keeps Mono's per-user state separate from your normal account and lets you practise both directions without changing the real trust store:
$ test_home=$(mktemp -d /tmp/setreg-home.XXXXXX)
$ HOME="$test_home" setreg
$ HOME="$test_home" setreg 1 true
$ HOME="$test_home" setreg
$ HOME="$test_home" setreg 1 false
$ HOME="$test_home" setreg
Current configuration
1 Trusting Test Roots (Mono and Microsoft) FALSE
The temporary directory name is a placeholder generated by mktemp. Keep it private while testing, and remove it with your normal temporary-file housekeeping once you have finished. The final check should show FALSE. If changing HOME does not isolate the result on your build, stop rather than experimenting against your real account; the setting may be stored through another per-user location.
6. Avoid the common traps
- Do not confuse test roots with a fix for real certificates. A failed production TLS check should be investigated through the endpoint chain, hostname, clock and CA deployment. Trusting self-signed test roots changes policy; it does not repair any of those causes.
- Do not use feature numbers from memory. This installed manpage documents feature
1only. It is the test-root switch. Do not invent another number or pass a certificate filename. - Use the literal values accepted by the documented syntax. The verified examples use lowercase
trueandfalse. Keep the feature and value as separate shell arguments. - Do not reach for root first. The setting is for the current user. Elevated execution can modify a different user's environment and make the result harder to diagnose.
- Treat
-qcautiously. The manual describes it as limited console display, but this installed build still printed its banner and current configuration when invoked with-q. Do not write scripts that depend on it suppressing all output; check the exit status and configuration row instead.
Done means
- You confirmed the
setregbinary and installedmono-develversion. - You inspected feature 1 before changing it.
- You enabled test-root trust only for an authorised, controlled Mono test.
- You verified the setting after the change rather than trusting a banner or exit status alone.
- You restored the original value, normally
FALSE, when the test ended. - You did not use test roots as a production certificate workaround or alter a machine-wide service configuration.