Guides / Trust a self-signed certificate on Windows.
Guide
Trust a self-signed certificate on Windows.
Install the Root CA, not every leaf. Chrome and Edge on Windows read the system store.
Machine store vs user store
Services and other users need the machine store (certlm.msc). A single developer laptop can use the current-user store. Do not import a host leaf into Trusted Root.
Need the files first? Make a local CA then issue a host cert.
Written for operators who have to trust the box they just stood up. Private keys stay in the tab. Open the generator.