Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To make headless Chrome trust an internal HTTPS site in Selenium, import the issuing certificate into the NSS database used by the Chrome process running in the container. In SeleniumHQ’s current images that database is commonly /home/seluser/.pki/nssdb, and the image includes /opt/bin/add-cert-helper.sh. Because Chromium’s default NSS location is version- and user-dependent, confirm the exact image tag and runtime user before choosing a path. For a repeatable setup, build a derived Docker image rather than changing a temporary container.

Choose the certificate and trust scope first

The installation command depends on what the certificate represents. A root CA that signs internal server certificates is not interchangeable with an intermediate CA, a self-signed leaf certificate, or a client certificate used for mutual TLS.

Certificate you have Chrome action Typical purpose
Root CA Import into the browser NSS database with SSL CA trust Trust certificates issued by your internal PKI
Intermediate CA Import as a CA without the root-CA trust flag Complete a chain when the server omits or privately distributes an intermediate
Self-signed server certificate Import that server certificate with peer trust Trust one endpoint without installing an issuing CA
PKCS #12 client certificate and private key Import with pk12util Authenticate to a server requesting a client certificate

Use a public certificate or CA certificate supplied by your organization. Do not put a private key in the image merely to make Chrome trust a server; private keys are needed only for client authentication and should be handled through your secret-management process.

Why the NSS database matters

Chromium’s Linux certificate documentation states that “On Linux, Chromium uses the NSS Shared DB.” The location is not universal. Since Chromium M146, the generic default is $HOME/.local/share/pki/nssdb, but an existing $HOME/.pki/nssdb continues to be used. Selenium images may initialize the legacy path for their standard user even when the browser version has the newer generic default.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The decisive questions are:

  • Which Selenium image tag are you running?
  • Which Linux user launches Chrome?
  • Which NSS directory already exists for that user?

Importing a certificate into /root’s database will not automatically make it available to Chrome launched as seluser. Treat the selected image’s README and the running browser user’s existing database as authoritative.

Inspect the image and runtime user

  1. Pin an image tag. Avoid building from a moving latest tag. SeleniumHQ’s documentation observed an example tag such as 4.48.0-20260905; use the tag appropriate to your project and re-check its README when upgrading.
  2. Find the configured user. Inspect the image’s USER setting and your Kubernetes, Docker Compose, or CI override. Selenium’s standard node images commonly run Chrome as seluser, but a custom image may run another account.
  3. Check candidate databases. As that user, inspect $HOME/.pki/nssdb and $HOME/.local/share/pki/nssdb. Do not create a database in one home directory and expect another user to see it.
  4. Install NSS tools. The Selenium image guidance uses libnss3-tools, which provides certutil and pk12util.

Preferred method: build a custom Selenium image

SeleniumHQ recommends deriving a custom image when a certificate must always be present. A build-time installation survives container recreation, while a change made with docker exec disappears when the container is destroyed. The exact helper invocation can vary with the image tag, so inspect the README for your pinned image before copying its sample.

A representative Dockerfile for an image that contains Selenium’s helper is:

FROM selenium/standalone-chrome:<PINNED_TAG>

USER root
COPY internal-root-ca.crt /tmp/internal-root-ca.crt
RUN /opt/bin/add-cert-helper.sh /tmp/internal-root-ca.crt 
    && rm /tmp/internal-root-ca.crt

USER seluser

Use the helper supplied by the compatible Selenium image rather than assuming that a helper from another tag has identical arguments. Keep the certificate in your controlled build context or secret workflow, and remove temporary copies after the import.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build and run it

docker build -t selenium-chrome-internal-ca:1 .
docker run --rm --shm-size=2g selenium-chrome-internal-ca:1

The shared-memory setting is unrelated to certificate trust but can prevent Chromium crashes on constrained Docker defaults. Your Selenium orchestration may already set it.

Direct NSS import with certutil

Use this route when the helper is unavailable or when you need explicit control. First install the tool and identify the browser user’s database:

apt-get update && apt-get install -y libnss3-tools
certutil -d sql:/path/to/browser/nssdb -L

For a root CA that should issue SSL server certificates, Chromium documents:

certutil -d sql:/path/to/browser/nssdb 
  -A -t "C,," -n "Internal Root CA" 
  -i /path/to/root-ca.crt

The database path must belong to the user launching Chrome. If the database has not been initialized, start Chrome once as that user or initialize the database according to the Selenium image’s instructions before importing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Intermediate CA

Chromium’s documented trust fields for an intermediate CA are:

certutil -d sql:/path/to/browser/nssdb 
  -A -t ",," -n "Internal Intermediate CA" 
  -i /path/to/intermediate-ca.crt

An intermediate normally relies on a trusted root. Installing only the intermediate may still fail if the root is absent or the server sends an incomplete chain.

Self-signed server certificate

For a self-signed server certificate, Chromium documents peer trust:

certutil -d sql:/path/to/browser/nssdb 
  -A -t "P,," -n "Internal Service" 
  -i /path/to/server.crt

Do not reuse C,, blindly. The three trust fields cover SSL, email, and object signing; select flags for the certificate’s actual role.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Client authentication with PKCS #12

A client certificate and private key packaged as PKCS #12 are imported with pk12util, not as a server-trust CA:

pk12util -d sql:/path/to/browser/nssdb 
  -i /path/to/client-identity.p12

Protect the .p12 file and its password. This is a separate concern from trusting the server certificate.

Add the CA to the Linux system trust store when needed

NSS configuration covers Chromium. Command-line tools and other runtimes may instead read the operating system trust bundle. For Debian or Ubuntu images, Docker’s documented pattern is:

RUN apt-get update && apt-get install -y ca-certificates
COPY your_certificate.crt /usr/local/share/ca-certificates/
RUN update-ca-certificates

The certificate must be PEM encoded, use the .crt extension, and contain one certificate per file. Debian’s update-ca-certificates merges local certificates into /etc/ssl/certs and generates /etc/ssl/certs/ca-certificates.crt. Other distributions use different package and update commands.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

System trust and browser trust are related but distinct. A successful curl request proves that curl’s trust path works; it does not prove that Chrome’s NSS database contains the CA. Conversely, an NSS import does not guarantee that Python, Java, or another SDK trusts the same CA. Docker notes that some SDKs and frameworks require additional steps beyond the OS trust store; see Docker’s CA certificate guidance.

Runtime installation for temporary testing

You can copy a certificate into a running container and execute the helper or certutil interactively. This is useful for diagnosing a failing build, but it is not a deployment strategy. Docker explicitly warns that certificates added at runtime do not persist when the container is destroyed or recreated.

docker cp internal-root-ca.crt selenium:/tmp/internal-root-ca.crt
docker exec -u root selenium /opt/bin/add-cert-helper.sh /tmp/internal-root-ca.crt

After confirming the correct database and trust flags, move the commands into a Dockerfile and rebuild.

Verify trust from the actual browser

  1. Rebuild the derived image with the certificate.
  2. Start Selenium using the same user and entrypoint used in production.
  3. Navigate headless Chrome to the internal HTTPS URL with a Selenium test.
  4. Check that the page loads without an interstitial certificate error.
  5. Test a URL that exercises the full certificate chain, including any required intermediate.

Do not rely only on curl. The verification must use the Chrome process and NSS database that your test actually launches.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting certificate errors

Chrome still displays a certificate warning

  • Confirm the certificate is the issuing root or required intermediate, not an unrelated leaf certificate.
  • Confirm Chrome’s runtime user and import into that user’s database.
  • Check both candidate paths when upgrading to a Chromium version with the M146 default change.
  • Inspect the certificate’s subject, issuer, and expiration before importing.
  • Restart Chrome after changing its database.

certutil reports that the database cannot be opened

  • Install libnss3-tools.
  • Use the sql: prefix and an absolute path.
  • Run the command with permission to read and write the browser user’s database.
  • Initialize the database by starting Chrome as that user if the directory is absent.

update-ca-certificates ignores the file

  • Use PEM encoding and a filename ending in .crt.
  • Place it directly under /usr/local/share/ca-certificates/.
  • Keep one certificate in each file.
  • Use the update command for the image’s distribution, not an Ubuntu command copied into another base image.

The build works but recreated containers fail

The certificate was probably installed interactively at runtime or the derived image is not the image actually deployed. Put the import in the Dockerfile, pin and deploy that image tag, and verify the orchestrator is not replacing the user or home directory.

Chrome trusts the site but another tool fails

Install the CA in the operating system trust store as well, then follow any runtime-specific certificate instructions. Browser NSS and system bundles are separate stores.

Performance, portability, and security decisions

Approach Scope Persistence Portability
Selenium helper Chrome’s configured NSS database Persistent when run during image build Best fit for compatible Selenium images; check tag-specific syntax
Direct certutil Precisely selected Chromium database Persistent in a derived image Works when NSS tools and the correct path are known
System trust store All compatible OS clients Persistent in a derived image Distribution-specific commands and possible runtime extras
Runtime mutation Current container only Lost on recreation Useful for diagnosis, unsuitable for repeatable deployments

Installing a CA adds trust for every site whose certificate chains to that CA. Prefer the narrowest certificate authority appropriate for the environment, avoid disabling TLS verification, and keep images free of unnecessary private keys.

Or skip the browser setup

If your goal is simply a clean screenshot rather than running Selenium interaction, ScreenshotNeo provides a one-request alternative. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

cURL:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo API documentation for options such as full-page capture, CSS selectors, custom headers and cookies, waits, blocking rules, PDFs, signed links, asynchronous jobs, and bulk capture. Its MCP server lets Claude, Cursor, or another MCP client call take_screenshot, get_page_info, and capture_pdf. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Frequently Asked Questions

Where is Chrome’s certificate store in a Selenium container?

Use the database belonging to the user that launches Chrome. Selenium images may initialize /home/seluser/.pki/nssdb, while generic Chromium documentation also describes $HOME/.local/share/pki/nssdb for newer versions.

Should I import a server certificate or its CA?

Prefer the organization’s root or intermediate CA when available. Import a leaf certificate only when the service is intentionally self-signed and you understand the narrower trust scope.

Will adding the CA with update-ca-certificates configure Chrome?

Not necessarily. The OS bundle and Chromium’s NSS database are separate; test the actual headless Chrome process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.