Overview
Modern Android versions strictly isolate user-installed Certificate Authorities (CAs), refusing to trust them for HTTPS inspection in third-party applications. While several modules exist to copy certificates from user storage to the system store, most standard implementations utilize exposed tmpfs bind mounts over /system/etc/security/cacerts or Conscrypt APEX directories. Sophisticated root detection libraries (such as those found in banking applications and anti-cheat engines) scan /proc/mounts for these tmpfs overlays and flag the device as tampered.
Developed by YujiaCheng1996, Custom Certificates builds upon foundational work from AdGuard Certificate and Custom-Certificate-Authorities, while introducing specialized stealth integration. By partnering with meta-hybrid_mount, it injects user-installed certificates into the system authority store without leaving exposed tmpfs traces in process mount tables.
Explicit Module Incompatibilities
[!WARNING] Custom Certificates is strictly incompatible with
adguardcertandcustom-certificate-authorities.
Because all three modules attempt to control and mount the Android system CA certificate paths, flashing this module alongside either predecessor will cause mount collisions and broken certificate stores. You must completely uninstall existing certificate modules before installing Custom Certificates.
Stealth Integration (meta-hybrid_mount)
To prevent root detection suites from spotting certificate mounts:
- Install
meta-hybrid_mountthrough your root manager. - If using an older revision of
meta-hybrid_mount, ensure thatapexis explicitly included in its target partitions list. - Install Custom Certificates.
- The module leverages hybrid overlay mounting to present the modified certificate store seamlessly within the stock filesystem namespace.
Step-by-Step Certificate Installation
- Uninstall any older certificate promotion modules.
- Install Custom Certificates in Magisk, KernelSU, or APatch.
- Open Android Settings → Security & Privacy → More Security Settings → Encryption & credentials → Install a certificate → CA certificate.
- Select your root certificate file (e.g., from Burp Suite, AdGuard, or mitmproxy) and confirm installation.
- Reboot your device.
- On startup, the module harvests newly added certificates and mounts them into the system trust store.
Verification
To verify that your certificate is recognized system-wide:
- Open Settings → Encryption & credentials → Trusted credentials → System.
- Locate your custom certificate authority name in the list.
- Launch your target app through an interception proxy to confirm transparent HTTPS decryption.
