Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

How to block Firefox from importing OS Certificate Authorities

Posted on October 26, 2023October 26, 2023 by Martin Brinkmann

Mozilla’s Firefox web browser maintains its own root certificate store by default. The browser uses these as “trust anchors” and the functionality is essential for making sure that only trusted SSL/TLS certificates are used by the browser.

Starting in Firefox 120, Firefox will automatically trust operating sysdtem certificates installed by the user or an administrators.

The beta release notes offer the following explanation:

By default, Firefox now uses TLS trust anchors (e.g., certificates) added to the operating system by the user or an administrator. This works on Windows, macOS, and Android, and it can be turned off in the “Privacy & Security” section of Firefox settings, under “Certificates”.

Administrators may add certificates to the operating system for a number of reasons. Some applications and devices may require them to work properly, and they may also be required in development environments. Antivirus solutions on Windows may try and register with Firefox to monitor data.

Blocking Firefox from trusting OS certificates

Firefox block third-party root certificates installed by the user

Firefox users may disable the functionality in Firefox 120 and newer versions. It is enabled by default. To modify this setting, follow these instructions:

  1. Load about:preferences#privacy in the Firefox address bar to open the Privacy settings.
  2. Scroll down to the Security section.
  3. Locate Certificates there.
  4. Remove the checkmark from “Allow Firefox to automatically trust third-party root certificates you install”.

You can undo the change at any time by checking the box again.

Another certificate preference

Firefox supports an Enterprise root preference already. When the browser runs into a TLS connection error, it will enable this Enterprise Roots preference automatically. This imports “any root certificate authorities” that users or administrators have added to the operating system.

Firefox tries to connect again to the site that threw the error. If successful, Firefox will keep the preference enabled and thus also the imported certificates.

Here is how this automatic behavior gets disabled:

  • Load about:config in the Firefox address bar.
  • Click “Accept the Risk and Continue” if the warning page is displayed.
  • Search for security.certerrors.mitm.auto_enable_enterprise_roots.
  • Change the value from True to False with a double-click or by using the button.
  • Search for security.enterprise_roots.enabled.
  • Change the value from True to False.
  • Restart the Firefox web browser.

Closing Words

Most Firefox users may want to keep the default as these are designed to minimize connection errors and issues. Users who want to be in full control may disable the functionality, on the other hand.

Tags: firefox
Category: Security & Privacy

Post navigation

← O&O ShutUp10++ review: tame Windows’ data hunger
About Samsung’s Temporary Cloud Backup →

1 thought on “How to block Firefox from importing OS Certificate Authorities”

  1. Tom Hawack says:
    October 26, 2023 at 7:08 pm

    This “security.certerrors.mitm.auto_enable_enterprise_roots” is not new though Firefox 120beta may plan to set it to “true” as default. This pref has been available for years now and for sure here on Firefox 115+ ESR the pref is available such as in about:config and as an Enterprise Policy in about:policies#documentation which links to its definition at [https://mozilla.github.io/policy-templates/#certificates] which states :
    “Trust certificates that have been added to the operating system certificate store by a user or administrator.”. I’ve always set it to “false”, though “false” may have been up to FF120beta the default value, not sure.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • August 27, 2025 by Martin Brinkmann 0Patch promises to keep Microsoft Office 2016 and 2019 secure after official end of support
  • August 26, 2025 by Martin Brinkmann Starting next year, all Android apps need to be registered by verified developers, even sideloaded ones
  • August 24, 2025 by Martin Brinkmann Windows 11: Resuming apps from Android is coming, again
  • August 23, 2025 by Martin Brinkmann Google could go after YouTube Premium users who bought the subscription in another country
  • August 22, 2025 by Martin Brinkmann Ecosia latest to make an offer for Chrome, sort-of

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2025 Chipp.in Tech News and Reviews