docs

Trust the CA certificate

Install Hugin's CA so HTTPS traffic decrypts in your browser.

To read HTTPS, Hugin presents its own certificate for each host. Your browser only accepts that if it trusts Hugin's CA. Install the CA once and every HTTPS site decrypts.

Export the CA

hugin ca export

This writes the CA certificate and prints the path (-o/--output to choose the file, --print to print it to stdout). You install the certificate; the private key stays on your machine.

Hugin can also add and remove its CA from the system trust store for you:

hugin ca trust
hugin ca untrust

The CA lets its holder decrypt your TLS traffic. Trust it only in a browser or profile you use for testing, never share the CA key, and hugin ca untrust when you are done on a shared machine.

Install it in a browser

  1. Firefox

    Firefox has its own trust store: Settings → Privacy & Security → Certificates → View Certificates → Authorities → Import, pick the exported file, trust it for websites.

  2. Chrome / Edge / Safari

    These use the OS trust store — hugin ca trust handles it, or import the certificate manually (macOS Keychain Access, Windows Certificate Manager, or /usr/local/share/ca-certificates on Linux) and mark it trusted for SSL.

Browse any HTTPS site through the Proxy: if it loads with no warning and the flow shows decrypted in HTTP History, the CA is trusted. Back to the quickstart.

Last updated 2026-06-07.