> For the complete documentation index, see [llms.txt](https://docs.apica.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.apica.io/platform-docs/zebratester-scripting/zebratester-how-to-articles/how-to-import-the-zt-root-certificate-to-an-ios-device.md).

# How to Import the ZT Root Certificate to an iOS device

Recording iOS device (e.g., iPhone and iPad) sessions require that you have installed your self-generated CA root certificate on these devices. This is a quick review of the steps to get this on your iPhone or iPad.

### Transferring the Certificate <a href="#howtoimporttheztrootcertificatetoaniosdevice-transferringthecertificate" id="howtoimporttheztrootcertificatetoaniosdevice-transferringthecertificate"></a>

The first step is getting the CA root certificate on the device. You can **e-mail your CA root certificate** to an Apple iOS device or **put it on any Web server** and address its URL directly in Safari. You can even use an application that syncs to each device (e.g., Evernote/Dropbox, etc.) and save that certificate to your iPhone/iPad Files folder.

After clicking on the certificate in the e-mail, entering the URL in Safari, or clicking on the certificate in your iPhone/iPad, your CA root certificate can be imported:

### iPad <a href="#howtoimporttheztrootcertificatetoaniosdevice-ipad" id="howtoimporttheztrootcertificatetoaniosdevice-ipad"></a>

| **Step**                                                                                                                                                                                                                                                                                                                                                                                                                                             | **ScreenShot** |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-installprofile">Install Profile</h4><p>After you click on your certificate file, there will be a new Profile downloaded.</p><ol><li>Under Settings--> General, the “Profile Downloaded” will open a dialog to install the certificate.</li><li>Click Install</li></ol><p>You also can remove the Downloaded Profile if this was either mistakenly downloaded or a no longer needed Profile.</p> |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-enterpasscode">Enter Passcode</h4><ol><li>Enter your passcode to Continue</li><li>Do <strong>not</strong> enter your Apple ID password.</li></ol>                                                                                                                                                                                                                                               |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-ioswarning">iOS Warning</h4><ol><li>iOS will warn you that this certificate has no trust or a trusted Root CA</li><li>Since this is self-generated, you can install this certificate</li><li>iOS will ask for final confirmation before doing the install</li></ol>                                                                                                                             |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-profileinstalled">Profile Installed</h4><ol><li>Once completed, the Certificate will read now as Verified.</li><li>Click More Details to check.</li></ol>                                                                                                                                                                                                                                       |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-zebratesterrootcasamplecert">ZebraTester Root CA Sample Cert</h4><p>All the details originally provided at certificate creation should be listed here.</p>                                                                                                                                                                                                                                      |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-settings">Settings</h4><p>You can find the Configuration Profiles underneath the <strong>Settings</strong> → <strong>General</strong> → <strong>Profiles</strong> menus.</p>                                                                                                                                                                                                                    |                |

***

### iPhone <a href="#howtoimporttheztrootcertificatetoaniosdevice-iphone" id="howtoimporttheztrootcertificatetoaniosdevice-iphone"></a>

| **Step**                                                                                                                                                                                                                                                                                                                                                                                                        | **ScreenShot** |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------- |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-settings-profiledownloaded">Settings: Profile Downloaded</h4><p>After you click on your certificate file, there will be a new Profile downloaded.</p><ol><li>Under <strong>Settings,</strong> → “<em>Profile Downloaded</em>” will open a dialog to install the certificate.</li><li>Click the right “<strong>></strong>” to start Installation.</li></ol> |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-installprofile.1">Install Profile</h4><ol><li>Notice that the Profile has a <strong>Not Verified</strong> label beneath it.</li><li>Click <strong>Install</strong></li></ol><p>You also have the option to <em>Remove the Downloaded Profile</em> if this was either mistakenly downloaded or a no longer needed Profile.</p>                              |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-enterpasscode.1">Enter Passcode</h4><ol><li>Enter your passcode to Continue</li><li>Do <strong>not</strong> enter your Apple ID password.</li></ol>                                                                                                                                                                                                        |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-ioswarning.1">iOS Warning</h4><ol><li>iOS will warn you that this certificate has no trust or a trusted Root CA</li><li>Since this is self-generated, you can install this certificate</li><li>Click <strong>Install</strong></li><li>iOS will ask for final confirmation before doing the install</li><li>Click <strong>Install</strong></li></ol>        |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-profileinstalled.1">Profile Installed</h4><ol><li>Once completed, the Certificate will read now as Verified.</li></ol>                                                                                                                                                                                                                                     |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-profileforzebratesterrootcasamplecert">Profile for ZebraTester Root CA Sample Cert</h4><ol><li>Click <strong>Profile</strong> –> More to see the certificate.</li><li>Drill down again to get certificate details.</li></ol><p>All the details originally provided at certificate creation should be listed here.</p>                                      |                |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-zebratesterrootcasamplecert.1">ZebraTester Root CA Sample Cert</h4><p>All the details originally provided at certificate creation should be listed here.</p>                                                                                                                                                                                               |                |

***

### Trust <a href="#howtoimporttheztrootcertificatetoaniosdevice-trust" id="howtoimporttheztrootcertificatetoaniosdevice-trust"></a>

Trust manually installed certificate profiles in iOS In iOS 10.3, and later, when you manually install a profile that contains a certificate payload, that certificate isn't automatically trusted for SSL.

The Screenshots for

*You must manually turn on trust for SSL when you install a new profile.*

| **Step**                                                                                                                                                                                                                                                                                                                                                                                             | **Screenshot**                                                                                                                                       |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-certificatetrustsettings">Certificate Trust Settings</h4><p>If you want to turn on SSL trust for a certificate:</p><ul><li>Go to <strong>Settings > General > About > Certificate Trust Settings</strong></li><li>Find the <strong>Enable Full Trust For Root Certificates</strong> section.</li><li>Enable trust for the certificate</li></ul> | <h4 id="howtoimporttheztrootcertificatetoaniosdevice-iphone.1">iPhone</h4><hr><h4 id="howtoimporttheztrootcertificatetoaniosdevice-ipad.1">iPad</h4> |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-rootcertificatewarning">Root Certificate Warning</h4><ul><li>Click <strong>Continue</strong></li></ul>                                                                                                                                                                                                                                          | <h4 id="howtoimporttheztrootcertificatetoaniosdevice-iphone.2">iPhone</h4><hr><h4 id="howtoimporttheztrootcertificatetoaniosdevice-ipad.2">iPad</h4> |
| <h4 id="howtoimporttheztrootcertificatetoaniosdevice-certificatetrustsettingscompleted">Certificate Trust Settings Completed</h4>                                                                                                                                                                                                                                                                    | <h4 id="howtoimporttheztrootcertificatetoaniosdevice-iphone.3">iPhone</h4><hr><h4 id="howtoimporttheztrootcertificatetoaniosdevice-ipad.3">iPad</h4> |

**Recommendation**

Apple recommends deploying certificates via Apple Configurator or Mobile Device Management (MDM). Certificate payloads installed with Configurator, MDM, or as part of an MDM enrollment profile are *automatically trusted* for SSL.
