Smile Certificate Authority

Internal Smile sites — the wiki, the helpdesk, and all resources on .intranet — are secured with Smile's private Certificate Authority (CA). Your device must be configured to trust this root certificate once. After that, security warnings will stop appearing for all internal Smile services.

If your browser warned you on the way to this page, stop and ask the IT department. This page is served with the same certificate, so a warning here means something is wrong that installing a file will not fix.

Download smile-root-ca-g2.crt — one file, the only one you need. Valid until 30 December 2029.

Verify what you downloaded matches what we published. SHA-256 fingerprint:

FC:E0:92:73:9A:2D:FA:C7:7E:89:D2:28:A6:68:C7:F6:A9:3C:E5:54:A0:27:C9:97:6C:A2:F0:A8:31:70:20:7B

Note: If you installed this certificate before September 2026, please install it again. It was renewed with the same key, and the new file replaces the old entry.

The warnings this fixes

Chrome security warning
Firefox security warning
Internet Explorer security warning

You should never see these on a Smile address. Do not click through them.

↑ Back to top

Windows

On Windows, system-level certificate trust is shared across Microsoft Edge, Google Chrome, and other native applications.

Open the downloaded smile-root-ca-g2.crt file and follow the import wizard.

The one step that matters: place the certificate in Trusted Root Certification Authorities, not wherever Windows offers by default.

Open certificate
Click Install Certificate
Store location selection
Choose Place all certificates in the following store
Select Trusted Root Certification Authorities
Confirm store selection
Complete wizard
Security warning confirmation
Import successful notification

Once completed, close every browser window and open it again.

↑ Back to top

Linux

On a Smile Linux workstation (Smilebuntu)

Nothing to download. The certificate arrives automatically via the smile-ca package and stays current on its own.

If a Smile site still warns you, the machine is not receiving updates. Run the two commands from Setting up or updating a machine on the wiki — they will fix package updates as well as the certificate.

On other Linux distributions

Download smile-root-ca-g2.crt and install it into your system trust store:

Debian / Ubuntu / derivatives:

sudo cp smile-root-ca-g2.crt /usr/local/share/ca-certificates/
sudo update-ca-certificates

RHEL / CentOS / Fedora:

sudo cp smile-root-ca-g2.crt /etc/pki/ca-trust/source/anchors/
sudo update-ca-trust

↑ Back to top

MacOS

Using Keychain Access

  1. Download smile-root-ca-g2.crt.
  2. Open Keychain Access and drag & drop the downloaded file into the login (session) or System keychain.

    Drag and drop certificate into Keychain Access
  3. Find Smile Root CA G2 in the list and double-click it. Expand the Trust section and set When using this certificate (or Secure Sockets Layer (SSL)) to Always Trust (Toujours approuver).

    Set certificate trust to Always Trust in Keychain Access
  4. Close the dialog and authenticate with your macOS administrator password when prompted.
  5. Restart your browsers.

Using Terminal (alternative)

You can also install and trust the root certificate in one command:

sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain smile-root-ca-g2.crt

↑ Back to top

Browsers (Firefox & Chrome)

Most modern web browsers (Safari, Chrome on macOS/Windows, Edge) automatically use the operating system trust store configured above. Some browsers maintain or support their own independent certificate stores:

Firefox

Firefox maintains its own certificate list. Open the downloaded file in Firefox (or go to Settings > Privacy & Security > Certificates > View Certificates... > Authorities tab > Import...) and tick Trust this CA to identify websites.

Firefox CA trust dialog

Chrome on Linux

If your browser does not use the system store directly, navigate to chrome://settings/certificates, open the Authorities tab, choose Import, and select the file you downloaded.

Chrome certificates authorities tab
Chrome certificate file selection
Chrome trust settings confirmation

↑ Back to top

System Administrators & Servers

Command-line installation

Install the root certificate directly into the system trust store:

Linux:

curl -fsSLo /usr/local/share/ca-certificates/smile-root-ca-g2.crt \
     https://pki.smile.fr/smile-root-ca-g2.crt
update-ca-certificates

Windows (elevated prompt):

certutil -addstore -f Root smile-root-ca-g2.crt

macOS (Terminal):

sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain smile-root-ca-g2.crt

Server certificate chain

A server that presents its own certificate also needs the issuing intermediate in its chain — smile-chain-g3.pem holds the intermediate and the root together. Server certificates are issued over ACME from the internal CA; ask the DSI team for the directory URL and the role for your DNS zone.

Additional files & checksums

The remaining files here are for specific cases — historical names kept for automation that still uses them, and the previous issuing CA. They are described on the wiki: Smile Certificate Authority. Checksums for everything served here are in SHA256SUMS.

↑ Back to top