Install DoD Certificates
A plain-English walkthrough for every platform. Get the certificates and the InstallRoot tool from the official DISA source — CAC Help is an independent guide and does not host, bundle, or run anything on your machine.
Always download from the official source. The DoD certificate bundle and the InstallRoot tool come from cyber.mil (DISA PKI/PKE → Tools). On a government or work computer, check with your IT / help desk first — the certificates are often already managed for you, and installing them yourself may be against your organization's IT policy.
Windows
Use DISA's official InstallRoot tool — it's digitally signed and installs the current DoD certificate authorities for you.
Download only from the official source. DoD certificates and the InstallRoot tool come straight from DISA at public.cyber.mil. CAC Help does not host, bundle, or run anything on your machine — we just show you the official steps and help you fix what breaks. On a government or work computer, check with your IT / help desk first: the certificates are often already managed for you, and running your own install may be against policy.
Steps
- Check with your IT / help desk first — managed (GFE) machines usually already have DoD certs pushed.
- Download InstallRoot from the official cyber.mil Tools page above and run the installer.
- In InstallRoot, install the DoD certificate group (add ECA only if your agency issues ECA-based cards).
- Restart your browser, insert your CAC, and visit a .mil site. Choose the right certificate when prompted (IDENTITY for general sign-on, EMAIL for webmail, SIGNATURE for PDF signing).
Prefer to do it by hand? Download the official DoD PKCS#7 certificate bundle (.zip) from cyber.mil, extract the .cer files, then open certmgr.msc and import the DoD Root CA certs into Trusted Root Certification Authorities and the intermediates into Intermediate Certification Authorities.
What gets installed
- DoD Root CA 3, 4, 5, 6 — the trust anchors for everything .mil
- DoD Intermediate CAs (DOD ID CA, DOD EMAIL CA, DOD SW CA, etc.) — the certs that chain CAC identity certs to a root
- (Optional) External Certification Authority (ECA) roots — only if your agency uses ECA-issued CACs/PIVs
These are installed into your user certificate store (Cert:\CurrentUser\Root on Windows, login keychain on macOS, NSS database on Linux). No admin/sudo required for the recommended user-only install path.
After install
- Restart your browser (all windows).
- Insert your CAC and visit a .mil site — pick the right certificate when prompted (IDENTITY for general sign-on, EMAIL for webmail, SIGNATURE for PDF signing).
- If a site still says "certificate required," check your OS-specific guide — there may be one more browser-level step.
Why you can trust this
Every download on this page points to an official DoD / DISA source — public.cyber.mil and dl.dod.cyber.mil. CAC Help never hosts, bundles, modifies, or runs DoD certificates or install scripts on your machine. We just explain the official steps and help you fix what breaks.
Installing root certificates is a high-trust action. Only download them from the cyber.mil links above, and if you are on a government-furnished or managed computer, follow your organization's IT policy and ask your help desk first — your certificates may already be installed for you.