SiteShadow
Back to vulnerability library

CERT01 Embedded CA Bundle

What this means

SiteShadow flagged custom/embedded certificate authority (CA) bundles or trust overrides that replace (or expand beyond) the OS trust store.

Why it matters

Safer examples

1) Prefer OS trust store where possible

Rely on the platform's CA store and keep it updated.

2) If you need custom trust (enterprise), scope it tightly

3) Avoid "fixing TLS issues" by weakening verification

Solve certificate distribution/CA installation issues instead of disabling TLS verification (see T01).

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Request access View coverage