Skip to content

Certificate not trusted

The Certificate screen in the sidebar is the source of truth. It checks trust the way macOS does — by building a certificate chain and asking the system to verify it — rather than by looking for the certificate in your keychain.

The certificate exists but macOS doesn’t trust it, so HTTPS passes through unread and apps refuse HTTPGlass’s certificate (rows read Untrusted). Click Install & Trust again and confirm the authorization prompt. If you cancelled the prompt the first time, that’s all it takes.

An older HTTPGlass root is still in your keychain

Section titled “An older HTTPGlass root is still in your keychain”

If you deleted ~/Library/Application Support/HTTPGlass, or restored an old backup, HTTPGlass generates a new root — but the old certificate can still sit in your login keychain, trusted, with the same name. Keychain Access then shows HTTPGlass CA as trusted while nothing decrypts, because the app signs with the new one.

The Certificate screen warns when it finds older HTTPGlass roots. Clicking Install & Trust removes them and trusts the current one.

If the status reads Trusted and a particular program’s rows read Pinned, the problem is that program, not the certificate:

If you trusted the root after the app had already been refused, click Try Again in the inspector so HTTPGlass attempts that host again on its next connection.

  • Check the date and time. A certificate has a validity window; a Mac with the wrong system date can reject it as expired or not yet valid.
  • Look for an error under the button. If macOS rejected the change, the Certificate screen shows the error it returned. Contact support with that message and your macOS version.