Troubleshooting website display or functionality issues in Edge on Windows 11
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
I am investigating how Microsoft Edge discovers client certificates for mTLS authentication.
I have observed the following behavior:
CurrentUser\My appears correctly in the Edge certificate selection dialog.CurrentUser\My to LocalMachine\My, it no longer appears in the Edge certificate selection dialog.LocalMachine\My successfully.My questions are:
LocalMachine\My?LocalMachine\My to be eligible for selection?CurrentUser\My, or are machine-store certificates also supported under certain conditions?Any clarification or official documentation would be greatly appreciated.
Thank you.
Troubleshooting website display or functionality issues in Edge on Windows 11
Hello Ariel, Yu Lan,
Welcome to Microsoft Q&A forum.
For a quick answer, for client certificates, you should left them at CurrentUser\My.
As I checked, Edge currently doesn't state LocalMachine\My for TLS certificate picker, so I wouldn't say that it is supported. And yes, there is absolutely extra certificate selection requirements beyond the normal TLS picker. However, I wouldn't be sure if satisfying those requirements can make LocalMachine\My available for selection.
About the CurrentUser\My, yes, it is special. The LocalMachine inherits all information and certificate to all stores, except for CurrentUser\My. So when you move certificate, the one in localMachine might not be accessible by CurrentUser, which Edge taking from.
I hope this clarifies.