256-bit AES - the same standard that protects banking transactions

0%
· 12 min read

Mincifry Certificates: What They Are, Why You Are Asked to Install Them, and How

In short: the Mincifry certificates are two service files - the root Russian Trusted Root CA and the issuing Russian Trusted Sub CA - that teach your device to trust Russian sites which have moved to domestic TLS certificates. Without them the browser shows “your connection is not private” on some bank and government sites. They must be downloaded from one single place, the official Gosuslugi page gosuslugi.ru/crt, which has the files and step-by-step instructions for every system. There is also a route with no installation at all - Yandex Browser, which has the support built in. Below: what this is in human terms, whether it is safe, and the installation per device.

Why banks and Gosuslugi ask you to install certificates

If VTB, Sberbank or Gosuslugi suddenly ask you to “install the Mincifry certificates”, it is neither a virus nor a scam - although fraudsters do exploit the topic, which is covered below. The reason is technical: any site with a padlock in the address bar proves it is genuine with a certificate issued by a certification authority. Russian sites used to get their certificates from international authorities; since 2022 that has been unavailable, and some services moved to certificates from the Russian national certification authority. The problem is that your phone and computer know only the international authorities out of the box - the Russian one is a stranger to them. Installing the two Mincifry files adds it to the list of trusted authorities: after that, sites on Russian certificates open as usual, with the same encryption.

The symptoms that you need these certificates specifically: “your connection is not private”, “cannot establish a secure connection”, an HTTPS error when signing in - on a bank or government site, while the rest of the internet works.

Should you install them: an honest breakdown

This is the main question of the topic, and it deserves a straight answer rather than a shrug.

What makes people uneasy. A root certificate is a thing with broad powers: the authority you have trusted can technically issue certificates for any site. The theoretical risk people discuss is the possibility of substituting the certificate of a particular site in order to read the traffic - a “man in the middle”. This is not a paranoid invention: that is how the technology of root certificates works, any of them, not only Russian ones.

What practice says. Over the years of use there have been no publicly confirmed cases of Russian root certificates being abused to intercept traffic; modern browsers and apps additionally protect critical connections with checks of their own. What is confirmed for certain is the other side: without the certificates, the personal accounts of some banks do not work - which means a VTB client or a Gosuslugi user has essentially no choice.

The sensible middle ground the cautious take: do not install the certificates into the system, and use Yandex Browser only for banks and government services - the support is built in there, and the trust is confined to one browser rather than the whole device. The rest of the internet carries on in your usual browser unchanged. If you need banking apps rather than sites, though, installation into the system is usually required.

Which services ask for the certificates

ServiceWhere it shows up
VTB and VTB OnlineSigning in to the site and the account - asks for them more often than anyone
GosuslugiSome sections and sign-ins
Sberbank and SberBank OnlineSigning in to the site
Alfa-BankSigning in to the account
Russian RailwaysBuying tickets on the site
Yandex servicesIndividual services and sign-in

The list is growing - services move to Russian certificates gradually, so “it worked without them yesterday and asks for them today” is a normal situation, not a fault. The full current list of sites running on Russian certificates is published on that same official page, gosuslugi.ru/crt.

⚠️ The certificates are downloaded only from gosuslugi.ru/crt. A search for “download mincifry certificate” returns third-party sites, and links circulate in messengers and SMS - phishing turns up among them: under the guise of a certificate you can receive anything at all. There is one official source, it is free and it does not require signing in.

Which is better - the Mincifry certificates or Yandex Browser

A literal question from search, and the answer is short. Yandex Browser - if what you need is bank sites and Gosuslugi from a computer or a phone and you do not want to install anything into the system: open it there and it works. Installing the certificates - if you need banking apps, a different favourite browser, or services that ask for the certificate outside the browser. You can combine them: the browser today, the certificates later when you need them.

How to install the Mincifry certificate on an iPhone

Let us start with why the iPhone gets its own instructions: on iOS the installation has two steps, and almost everyone skips the second - then complains that “I installed it and it does not work”.

  1. Open gosuslugi.ru/crt in Safari and download the profile with the certificates for iOS. The system will ask permission to download the profile - allow it.
  2. Settings → Profile Downloaded, it appears at the top → Install → enter your passcode.
  3. The key step everyone skips: Settings → General → About → Certificate Trust Settings → turn on the switch next to Russian Trusted Root CA. Without this the certificate is installed but does not work.
  4. Clear the browser cache and restart it - without that the browser may keep showing the old error even when the certificates already work. Then open the bank site: the error should be gone.

How to install on Android

  1. Open gosuslugi.ru/crt and download the certificates for Android - two files or an archive.
  2. Settings → Security, or “Security and privacy” → Encryption and credentials → Install a certificate → “CA certificate”.
  3. The system will warn you that a CA certificate carries broad powers - that is the standard warning when installing any root certificate. Confirm and pick the downloaded file. If the phone asks for a name, enter “Russian Trusted Root CA”, and under the purpose choose “VPN and apps”. Repeat for the second file, the Sub CA. After installing, clear the browser cache - otherwise the old error may keep showing out of inertia.
  4. On the Samsung, Xiaomi and Honor shells the items may be named slightly differently - look for “install from storage” or “install from device storage” in the security section.

How to install on a computer

The simplest route on Windows: gosuslugi.ru/crt has an automatic installer - download it, run it, two clicks, restart the browser. The manual way, if you need it: download both certificates → open each with a double click → “Install certificate” → the “Trusted Root Certification Authorities” store for the root one and “Intermediate Certification Authorities” for the issuing one.

Mac - the same page has instructions: installation through Keychain with trust enabled manually, the same logic as on the iPhone.

⚠️ A trap of its own is Firefox. It has its own certificate store and does not see the system one: install them in Windows and Firefox will still complain. The cure is inside the browser itself: Settings → search for “Certificates” → “View Certificates” → “Import” → pick both downloaded files and tick “Trust this CA to identify websites”. The same applies to some other browsers with a store of their own.

How to check whether the certificates are already installed

A question thousands of people ask, with no clear answer in search results. Two ways.

The practical one - open a site that used to complain, the VTB sign-in for example: if it opens without an error, the certificates are in place and working.

The precise one - the gosuslugi.ru/crt page itself has a check, and by hand it goes like this: on an iPhone, Settings → General → About → Certificate Trust Settings, where Russian Trusted Root CA must be switched on; on Android, Settings → Security → Encryption and credentials → Trusted credentials → the “User” tab, where both entries must be present, Russian Trusted Root CA and Russian Trusted Sub CA - one without the other means the installation was not completed, so repeat it for the missing file; on Windows, search for “Manage user certificates” → Trusted Root Certification Authorities.

It will not install, or you installed it and it did not help

It will not install: check that you are downloading from gosuslugi.ru/crt itself and that the file downloaded completely; on an iPhone the profile installs only from Safari, not from Chrome; on Android, if the file “cannot be read”, download the certificates one by one rather than as an archive.

You installed it and the site still complains: on an iPhone go back to the “Certificate Trust Settings” step - in nine cases out of ten that is it; restart the browser completely, or better the device; check the date and time on the device and set it to “automatic”, because with a wrong clock no certificate passes validation; and make sure the error really is about the certificate rather than “the site will not open at all” - those are different diagnoses, and why a site will not open at all we have covered separately.

I installed the certificates and my VPN stopped working

A rare but real scenario with a simple explanation: the certificates are almost never to blame here - it coincided in time. Installing certificates does not change network settings and does not touch VPN connections. If the connection stopped coming up after the installation, the cause is elsewhere: work through the diagnosis of why a VPN is not working - from the date and time, which people often change while fiddling with certificates, to the protocol. And if your connection is sensitive to interference from the network, look towards protocols with masking such as VLESS: at Tainet they are in every subscription, connect in the Telegram bot or in your account.

How to remove the Mincifry certificates

Knowing how to take them off is half the peace of mind when putting them on, so here it is, honestly and symmetrically.

iPhone: Settings → General → VPN & Device Management → the profile with the certificates → Remove Profile, plus the passcode.

Android: Settings → Security → Encryption and credentials → Trusted credentials → the “User” tab → select the certificate → Remove.

Windows: “Manage user certificates” → Trusted Root Certification Authorities → find Russian Trusted Root CA → delete, and the issuing one under “Intermediate Certification Authorities”.

After removal, sites on Russian certificates will start showing the error again - that is expected.

And if you are abroad

Then the certificates are only half the answer: banks and Gosuslugi also look at where you are signing in from, and they turn away foreign addresses regardless of certificates. The full recipe for life abroad is how to access Gosuslugi from abroad: it covers the Russian IP, signing in without SMS and backup codes; the certificate part you have already closed with this article. A stable Russian address for that is what Tainet does as its main job: the first 7 days are free, enough to check that you get into your bank before paying.

Frequently asked questions

What is Russian Trusted Root CA? That is the Mincifry root certificate - the technical name, and exactly what you will see in your device’s certificate list. The second file, Russian Trusted Sub CA, is the issuing one, the working pair of the root. If you see these names in the settings, the certificates are installed.

Do the certificates spy on me? The fear of surveillance is the most common one in this topic, so here is the honest answer. A certificate by itself is not a program: it does not run, it does not collect data, and it cannot “spy” in the everyday sense. The risk under discussion is a different one, covered in the “Should you install them” section - the theoretical possibility of substituting sites’ certificates. If that risk matters to you, use the browser route: the trust stays within the bounds of one browser. The technically minded confine the trust even more narrowly - professional communities describe ways to allow a certificate only for specific sites.

Can I not install them? You can. Then some bank and government sites will show a connection error - either open them in Yandex Browser, or use the apps, where the service handles the question of trust itself. The choice stays yours, and “not until I need to” is a legitimate strategy.

Do I need to install them again on a new phone? Yes: the certificates live on the device, not in the account. A new device means a new installation from the same official page.

In summary

This guide covers the installation in full, but if something still behaves oddly after all the steps, check the “did not help” section first. And one general observation to close with: certificates settle the question of trust, but not of stability. If you need Russian services reliably from anywhere - home, travel, abroad - that is exactly the job Tainet does: a stable connection with a Russian address, the first 7 days free. For questions about our part, support answers with real people; honestly, we cannot advise on the certificates themselves or on other people’s banks.