Use AdGuard on mobile devices often requires installing a special root certificate for HTTPS traffic filtering to work correctly. However, there are situations when this digital ID becomes redundant, outdated, or causes conflicts with other applications. Removing a certificate is a necessary procedure if you refuse to use the DNS service or encounter security validation errors in the browser.
The process of uninstalling digital keys on Android is not always obvious, since the system hides these settings deep in the security menu. Incorrect actions can lead to traffic no longer passing through the filter, or, conversely, the system will block connections, considering them unsafe. In this article, we will look in detail at all the ways to clear the trust store.
It is important to understand that there is a difference between the certificate of the application itself and the user root certificate that is embedded in the system. We will focus specifically on the system storage, where resides AdGuard CA. Are you ready to change the security settings of your smartphone?
Why do you need to remove certificates at all
The main reason why you may need to remove AdGuard CAis related to a change in security policy or refusal to use the HTTPS filtering function. When an application establishes its root of trust, it gains the ability to decrypt and analyze encrypted traffic. If you no longer plan to use this feature, leaving the certificate on the system creates a potential, albeit hypothetical, attack vector.
In addition, the presence of third-party root certificates can cause problems when working with banking applications and corporate software. Some security apps, such as Google SafetyNet or banking clients, can block work on devices where unverified certificate authorities are installed. This is a mechanism for protecting against data interception (Man-in-the-Middle).
โ ๏ธ Attention: Removing system certificates may require superuser rights (Root) on some versions of Android, especially if the certificate was installed as a system certificate and not a user one.
It is also worth noting that if the operation itself fails data-i="43">, reinstalling the application does not always clear the old keys. The accumulation of stale records in the storage can lead to connection errors. Therefore, a complete wipe before a new installation is a good mobile device administration practice. AdGuard, reinstalling the application does not always clear the old keys. The accumulation of stale records in the storage can lead to connection errors. Therefore, a complete wipe before a new installation is a good mobile device administration practice.
Searching for the section with certificates in the settings
Interface Android varies greatly depending on the shell manufacturer. Somewhere the settings are hidden deep in the โSecurityโ menu, and somewhere they are placed in a separate item โEncryption and Credentialsโ. The first step is always to find the desired section through a global search in settings.
You need to find an item called Encryption and credentials or Security. Inside this section, look for subsection Trusted credentials. This is where the list of all certification authorities that your phone trusts when establishing secure connections is stored.
The system usually divides certificates into two categories: system (pre-installed by the manufacturer) and user. We are interested in the tab Custom. If you previously installed AdGuard with root access or through special scripts, the certificate may also be displayed in the system list, but most often it is among the user ones.
Use the search bar at the top of the settings menu by entering the word "certificate" or "credential" to instantly go to the one you need section, bypassing long menu lists.
On devices with clean Android (Pixel, Motorola) the path usually looks like this: Settings โ Security โ Advanced โ Encryption and Credentials โ Trusted Credentials โ User data-i="70">Settings โ Biometrics and security โ Other security settings โ Install from device. On smartphones Samsung the path may differ: Settings โ Biometrics and security โ Other security options โ Install from device (controls are often located here).
Standard removal procedure through the interface
Once you are in the list of user certificates, you will see a list of installed certificate authorities. Find an entry in the list with the name AdGuard or AdGuard CA. The name may vary depending on the version of the application, but "AdGuard" should be present.
Click on the name of the certificate. A window will open with detailed information about it: installation date, key fingerprint and expiration date. At the bottom of this window or in the menu (three dots in the corner) there should be a button Delete or a trash can icon. The system will ask you to confirm the action, as this affects the security of the device.
- ๐ Find the certificate with the name AdGuard in the list of user ones.
- ๐๏ธ Click on it and select the option
Deletein menu that opens. - โ Confirm the action by entering your PIN code, pattern or fingerprint.
After confirmation, the certificate will be immediately deleted from the storage. Browsers and applications will no longer trust traffic signed with this key. If AdGuard is still active and trying to filter traffic, you will begin to receive SSL errors in the browser, which signals that your settings are out of sync.
โ๏ธ Checking the removal of the certificate
Removal through the settings of the AdGuard application itself
Often the easiest way to remove a certificate is to use the built-in tools itself AdGuard. The application has access to manage its configurations and can automatically clear the system storage when the corresponding function is disabled.
Open the application AdGuard and go to the Settingssection. Find the item responsible for HTTPS filtering or the network layer. This is usually called HTTPS filtering. Inside this menu there should be an option to manage the root certificate.
Settings โ Network Filter โ HTTPS Filtering โ Manage Certificates
If you click on button Delete certificate inside the application AdGuard will send a system request to delete its key from the storage Android. This is the most secure method, since the application itself controls the integrity of its settings.
โ ๏ธ Attention: If the delete button is inactive or the application reports an error, it means that the certificate was installed manually or the application's rights were limited by the system. In this case, use the method through the system settings.
Also in the application settings there is a full reset function. If you plan to delete AdGuard entirely, first go to settings, disable HTTPS filtering and only then delete the application itself. This will prevent dangling entries from appearing in the system.
What to do if the delete button is gray?
If the delete option is greyed out in the application, try turning off the HTTPS filtering switch first, wait a few seconds, and then turn it back on. Sometimes this updates the status of the certificate and unlocks the control button.
Problems with superuser rights (Root)
In some cases, especially on custom firmware or when using older versions of AdGuard, the certificate is installed in the system trusted authorities section. The normal user interface Android does not allow you to delete system certificates without superuser rights.
If you do not see the certificate in the "Custom" section, but it continues to affect the operation of the system, it is probably located in /system/etc/security/cacerts/. To work with this section, you need root access and a file manager with access to system folders, for example, Root Explorer or Mixplorer.
| Access type | Certificate location | Removal method | Risks |
|---|---|---|---|
| Custom | /data/misc/user/0/cacerts-added/ |
Through Android settings | Minimal |
| System (Root) | /system/etc/security/cacerts/ |
File manager with Root | High (brick) |
| Temporary | RAM | Restarting the device | None |
When deleting a system file manually, it is critical not to affect other files in the folder cacerts. Delete only the file that matches the certificate hash AdGuard. The error may cause the system to stop trusting any secure connections, including Google Play updates.
Manipulating the /system partition requires extreme caution. Always create a full backup (Nandroid backup) before deleting system certificate files.
Resetting network settings as an alternative method
If you cannot find a specific certificate or are afraid to delete something unnecessary manually, there is a more radical but effective method - resetting network settings. This operation clears all user certificates, Wi-Fi, Bluetooth and mobile network settings to the factory state.
To perform a reset, go to Settings โ System โ Reset settings โ Reset Wi-Fi, mobile data and Bluetooth settings. The path may differ on different devices, but the keywords โReset settingsโ and โNetworkโ must be present.
- ๐ก This operation will delete all saved Wi-Fi networks and Bluetooth pairs.
- ๐ All manually installed user certificates will be destroyed.
- ๐ Mobile hotspot settings will return to default values.
This is ideal if you are selling the device or transferring it to another user and want to ensure that all traces are removed AdGuard etc. network utilities. After resetting, the phone will require you to set up your Internet connection again.
โ ๏ธ Attention: Resetting network settings does not delete your personal files, photos or applications. However, you will have to re-enter passwords for all Wi-Fi networks to which you previously connected.
Remember that manufacturer interfaces may change. If you do not find an exact match of the menu items, be guided by the general meaning of the โResetโ or โRecoveryโ section. Always check the description of the action before pressing the final confirmation button.
Before resetting the network settings, take a photo of the important settings of the static IP address or DNS servers if you use them for work or specific tasks, in order to quickly restore them later.
Possible problems after deletion
After you successfully deleted the certificate AdGuard CA, you may experience a number of side effects. The most common one is SSL errors in the browser when trying to access certain sites. This happens if the application itself is still active and trying to filter traffic without a trusted key. In this case, the browser's security system blocks the connection because it cannot verify the authenticity of the site through the filter's intermediate certificate. The solution is simple: either completely uninstall the application AdGuard is still active and trying to filter traffic without a trusted key.
In this case, the browser's security system blocks the connection because it cannot verify the authenticity of the site through the intermediate filter certificate. The solution is simple: either completely uninstall the application AdGuardor disable the HTTPS filtering function in it.
You may also receive notifications from the security system stating that โThe network security policy has been changed.โ This is a normal reaction Android to a change in the composition of trusted bodies. The notification should disappear after rebooting the device.
What should I do if the certificate returns after deletion?
If the certificate AdGuard appears again immediately after deletion or reboot, check to see if the automatic installation feature is enabled in the application itself. This may also occur if you have device administrator (MDM) profiles installed that enforce certificate deployment. In this case, you need to delete the administrator profile in the security settings.
Is it possible to delete system certificates without Root?
Without superuser rights, deleting certificates from the system partition /system/ is impossible for Android security reasons. You can only remove certificates that have been added to the user section. If the certificate is on the system, only a factory reset (Full Wipe) will help, which will delete all data from the phone.
Does deleting a certificate affect the operation of a regular ad blocker?
A regular ad blocker working through a local VPN without HTTPS filtering will continue to work correctly. Removing a certificate only affects the ability to decrypt and filter protected traffic. Blocking by DNS or at the host level will not stop functioning.
How to check that the certificate has been definitely deleted?
To check, use online SSL verification services or try visiting a site that previously required a certificate to work through the filter. You can also use applications like SSL Checkerthat show the chain of trust for the current connection.
Do you need to restart your phone after deleting?
Although the system applies the changes instantly, it is recommended to restart the device. This ensures that all cached network settings are cleared, and applications begin to build trust chains anew, without the participation of the remote key AdGuard.