Select certificate type, target OS, and deployment method.
Certificate
Operating System
Deployment Method
Run in an elevated (Administrator) PowerShell terminal. The script downloads and installs the certificate from .
Or download and run manually:
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass .\install-ca-windows.ps1
Download the certificate then import it using certutil. Open Command Prompt as Administrator.
Step 1 — Download certificate
Step 2 — Import to Trusted Root store
Verify
certutil -store Root | findstr "Vinetu"
Push the certificate to all domain-joined machines. Requires Domain Admin rights.
Open GPMC and create a GPO
Run gpmc.msc → right-click target OU → Create GPO → "Vinetu CA Certificates" → Edit
Navigate to the certificate store
Right-click → Import → select
Link GPO and force policy update
gpupdate /force
Intune / Azure AD
Intune admin center → Devices → Configuration profiles → New → Platform: Windows 10 and later → Template: Trusted certificate → Upload → Destination: Computer certificate store — Root.
Run in Terminal. Installs the certificate into the System Keychain. Requires sudo.
Or download and run manually:
security commandInstalls the into the System Keychain as a trusted root. Requires sudo.
Step 1 — Download certificate
Step 2 — Add to System Keychain
Verify
security find-certificate -c "Vinetu" -a /Library/Keychains/System.keychain
For Jamf Pro, Mosyle, Kandji — push the via a Certificate payload.
Detects your distro (Debian/RHEL/Arch) and installs the certificate automatically.
Install the certificate using update-ca-certificates.
The file must use a .crt extension in /usr/local/share/ca-certificates/.
Install the certificate using update-ca-trust.
Install the certificate using trust extract-compat.
Verify
curl -v https://<internal-service>/ 2>&1 | grep -i "verify\|issuer"
Expected: Verify return code: 0 (ok)