Gov · banks · social · marketplaces

Site says “not secure”?
Install the Russian certificates

The official Ministry of Digital trusted certificates fix the trust error on Russian government, banking and marketplace sites. Installation takes a few minutes and needs no special skills.

Detected: Windows
Windows

The installer will do the work

Install for Windows

Files are verified with SHA-256 checksums

Or choose your system

Official certificatesChecked against the Gosuslugi source

Transparent installScripts are open for review

Certificates onlyNo third-party software installed

You install it once — and sites open in your favourite browser: Chrome, Firefox, Edge, Opera, Vivaldi, Brave and others.

How it works

Three clear steps

The site chooses a safe method for your system. You do not download certificates one by one.

1

Choose your system

We detect it automatically, and you can always change it.

2

Start installation

Files are fetched from the server and checked against known hashes.

3

Restart your browser

Websites using Russian certificates should then open normally.

Why this is needed

What certificates fix

Some foreign certificate authorities may stop serving Russian websites. A browser can then show a certificate error even while the website itself is online.

Important

Certificates only resolve trust errors. They do not bypass blocking, change DNS or add GOST cipher support to a standard browser.

Who it helps

When the sites you need won’t open

Usually this is a certificate-trust error, not blocking. Recognise your case?

Which sites it helps

  • Gosuslugi and government portals
  • Online banks: Sberbank, VTB, Alfa-Bank
  • Marketplaces: Ozon, Wildberries
  • Social networks: VK, Odnoklassniki
  • News sites and media
  • Other sites using Ministry of Digital certificates

What the error looks like

  • Your connection is not secure
  • The security certificate is not trusted
  • This site can’t provide a secure connection
  • ERR_CERT_AUTHORITY_INVALID
  • SEC_ERROR_UNKNOWN_ISSUER
FAQ

Common questions

Why does the browser say “Your connection is not secure”?

Russian sites moved to the Ministry of Digital (НУЦ Минцифры) certificates because foreign certificate authorities stopped serving them and began revoking. Browsers do not yet know this root certificate and show an error, even though the site itself works. After installing the Russian certificates and restarting the browser, the error disappears.

Is this safe? Is it a virus or surveillance?

It is a plain root certificate, not a program: it installs nothing, reads no files and does not track which sites you open. Like any root certificate it technically lets its owner sign a certificate for another domain, but there are no confirmed cases of the НУЦ root being abused, and banking apps and messengers are protected separately. The files here are unpacked from the official Gosuslugi publication and verified by SHA-256, and you can remove them at any time.

I installed it but the site still won’t open. Why?

Most often the browser was not fully restarted or is showing a cached page — close it completely and reopen. The second common reason is installing only one file: you need both the root (Russian Trusted Root CA) and the issuing one (Russian Trusted Sub CA). If you use Firefox, it has a separate store — see the Firefox question below.

Why are both a root and an intermediate certificate needed?

The browser builds a chain of trust: the site’s certificate is signed by an intermediate authority, which is signed by the root. Adding the root to your store is usually enough — the site normally sends the intermediate during the connection. But if a site is misconfigured and doesn’t send it, the browser can’t complete the chain, and a pre-installed intermediate saves the day. So the root is required and the intermediate is a safety net; on a computer the installer adds the whole set automatically.

Which browser needs it, and where does it already work?

Chrome, Edge, Opera and Safari read certificates from the operating-system store, so installing the certificate once into the system covers all of them. Firefox is the exception: it keeps its own store. After installing, close and reopen the browser fully.

Will it open YouTube, Instagram or blocked sites?

No. The certificates only remove the trust error on Russian sites that moved to the НУЦ Минцифры chain — this is not a VPN and not a way around blocking. Blocked resources work differently and are unaffected.

My online bank (Sber, VTB, Alfa) won’t open — will it help?

Yes, if the bank moved to the НУЦ Минцифры certificate — Sberbank, VTB, Alfa-Bank, PSB, RSHB and others did. Install the root and issuing certificates and restart the browser, and the bank’s web version opens again. The mobile app usually has the certificate built in and works without installing anything.

Android shows “Network may be monitored” — is that dangerous?

No, this is the standard Android notice that appears whenever a manually added certificate is present. On its own it does not mean you are being watched or that the phone is infected. The trust error shows up in the browser, while banking apps usually work without installing anything.

On iPhone the profile installed but says “Not Verified”.

On iPhone and iPad installation takes two steps: first you install the profile, then you separately enable trust for it. Open Settings → General → About → “Certificate Trust Settings” and turn on the switch next to “Russian Trusted Root CA”. Until that step the “Not Verified” status is normal.

Certificates don’t work in Firefox even though they’re in the system.

Firefox keeps a separate store per profile and does not use the system one by default. On a computer, open about:config and enable security.enterprise_roots.enabled, and Firefox will trust the system certificates. Or add both certificates manually: Settings → Privacy & Security → Manage Certificates → Authorities → Import.

A work computer without admin rights — what can I do?

You can add the root to the “Current User” → “Trusted Root Certification Authorities” store without admin rights, and Chrome and Edge will honor it for your account. If the computer is managed by organization policy and installation is blocked, it is best to ask your IT administrator.

Can I remove the certificates without weakening security?

Yes, you can remove them at any time via your system certificate manager (on iPhone, by deleting the profile). Adding this root does not weaken checks for other sites — they are still validated by their own certificate authorities. After removal, only Russian sites using the НУЦ Минцифры certificates stop opening.

How do I avoid fake certificates?

A real certificate is not a program: it installs nothing and never asks for your Gosuslugi or bank password. Scammers build fake sites with an “install a trusted certificate” banner and push malware instead. Take the files only from official sources — Gosuslugi, gu-st.ru or this page, where they are verified by checksums.

Support

Keep the project alive

The site is free. Donations and partners keep it running.

Partners