You are not reading the latest stable version of this documentation. If you want up-to-date information, please have a look at master.

Trusting Embassy CA On Windows

Unfortunately, Windows does not have mDNS support built-in, which is necessary in order to visit .local addresses, so we recommend using the Bonjour service. Check out this FAQ answer for details.

  1. Install Bonjour Print Services on your Windows machine.


    If you are experiencing issues after installing Bonjour, you might have had a previous or failed install. To fix:

    1. Check out this video:

    2. Uninstall Bonjour completely via system settings > remove programs

    3. Reinstall Bonjour Printer Driver package (download at

    4. Restart Windows

    5. Note: Uninstalling Bonjour via the setup package seems to be not enough to solve the issue. Bonjour must be uninstalled via windows system settings.

  2. Back in Windows, right-click the “Start” menu and select “Run”.

  3. Type in “mmc” and click “OK”. When prompted on the “User Account Control” window, select “Yes” to allow this program to run.

    Windows MMC

    Access the Windows Management Console

  4. When the Management Console opens, navigate to File > Add/Remove Snap-in.

    Windows Console Root

    Add Snap-in from Console Root

  5. Select “Certificates” in the left side menu, then “Add”. This will open another window.

    Add Certificates

    Add Certificates to selected snap-ins

  6. Select “Computer account” and click “Next. Leave defaulted options on the next screen and click “Finish”.

  7. When you return to the “Add or Remove Snap-ins” page, ensure “Certificates (Local Computer)” exists under “Console Root” in the “Selected snap-ins” section, then click “OK”.

    Snap-in Selected

    Certificates (Local Computer) is selected as snap-in

  8. In the left hand menu of the Management Console, navigate to Certificates (Local Computer) > Trusted Root Certification Authorities > Certificates.

    Certificates in Management Console

    Access Certificates in Management Console

  9. Right click on “Certificates”, then navigate to All Tasks > Import.

    Import certificate

    Select “Import” from Certificates sub-menu

  10. Click “Next” on the first page of the Certificate Import Wizard, then browse to the location where you saved the downloaded certificate and click “Open”.

    Import cert wizard

    Add downloaded certificate in the Certificate Import Wizard

  11. On the “Certificate Store” window, ensure that it says “Trusted Root Certificate Authorities” and click “Next”.

  12. Select “OK” when the import is successful.

  13. Verify the Embassy Local Root CA certificate is in the “Certificates” folder.

    Successful cert install

    Embassy Local Root CA imported into Certificate folder

  14. You can save the settings to the console if desired or cancel.