Trusted HTTPS for your UniFi UCG-Fiber console using mkcert
Every time I opened the UniFi UCG-Fiber console in my browser, I was greeted with a “This Connection Is Not Private” warning. It’s a minor annoyance, but it adds up. The gateway runs on a self-signed certificate by default, which no browser trusts out of the box. I decided to fix it properly using mkcert. It is a simple tool that generates locally-trusted development certificates. Here’s exactly how I did it, and how I got my other Macs, iPad, and iPhone to trust the certificate too.
Step 1: Create a Local DNS Entry in UniFi
Before anything else, you need a proper hostname to point at your UCG-Fiber. Accessing the console by IP address won’t work well with a certificate, so I created a local DNS record inside UniFi itself. Go to Network β Policy Engine, create a new DNS policy with type Host (A), set the domain name to something like ucg-fiber.home, and point it at your gateway’s local IP .
Once the DNS policy is saved, every device on your network will be able to resolve ucg-fiber.home without needing to touch their hosts file.

Step 2: Install mkcert
On your main Mac, install mkcert via Homebrew. If you don’t have Homebrew yet, grab it from brew.sh first. Also check out my full dev setup for Mac if you’re interested.
brew install mkcert mkcert -install
The mkcert -install command creates a new local Certificate Authority (CA) and installs it in your macOS system trust store. From this point on, any certificate you generate with mkcert will be trusted automatically by Safari, Chrome, and other system-level tools on this Mac.

Step 3: Generate the Certificate
Now generate the certificate for your chosen hostname. Navigate to a folder where you want to store the cert files, then run:
mkcert ucg-fiber.home
This creates two files: ucg-fiber.home.pem (the certificate) and ucg-fiber.home-key.pem (the private key). Take note of the expiration date so that you will know when to renew the certificate. You will also see later that the Unifi Cloud Gateway’s console will also note the expiration date of the certificate.

Step 4: Upload the Certificate to the UCG-Fiber Console
Log into your UCG-Fiber console and go to System β Control Plane β Console. Scroll down to the Certificates section and click Add New. Upload the .pem certificate file and the -key.pem private key file, then activate it.
Once uploaded, you’ll see the certificate listed with your hostname, its expiry date, a green valid indicator, and the option to set it as active.

Browse to https://ucg-fiber.home on your Mac and the certificate should already show as valid and trusted. I used Brave browser here to explicitly check the certificate when taking the screenshot. But if you want to check it when using Safari browser, it is now located under Safari β πConnection Security Details… on the menu bar.

Trusting the Certificate on Other Macs
Without the root CA installed, the second Mac will show the dreaded “This Connection Is Not Private” warning even though the certificate is valid on the first machine.

iCloud Keychain does not sync trusted root certificates between Macs. It syncs passwords, passkeys, and Wi-Fi credentials, but certificate trust settings are device-specific and stay local. So you’ll need to handle each Mac separately.
The easiest approach if you have mkcert installed on the other Mac is to copy across just the rootCA.pem file and run mkcert -install.
Technically you don’t need the rootCA-key.pem private key for this step. However, if you also want to generate new certificates from this Mac using the same CA, you’ll need theΒ rootCA-key.pemΒ as well. This is what I did since I rather simplify my workflow to always having to use the same root CA across work machines.
On your main Mac, run:
mkcert -CAROOT
This prints the path to the mkcert folder. You can then open it in Finder with open . after navigating there. AirDrop the rootCA.pem and rootCA-key.pem file to your other Mac.

On the second Mac, install mkcert as well. Then use mkcert -CAROOT also to get the mkcert folder.

On the second Mac, place the received rootCA.pem and rootCA-key.pem into the mkcert application support folder, most likekly at ~/Library/Application Support/mkcert/, replacing both the existing files there. Then run:
mkcert -install

That’s it. Reload https://ucg-fiber.home and the certificate will now be trusted on that Mac too.

Alternatively, if you don’t want to install mkcert on the other Mac at all, you can simply double-click the rootCA.pem in Finder to import it into Keychain Access, then manually set the trust to Always Trust. Either approach works. The mkcert route is just more convenient if you plan to generate more certs in the future.
Trusting the Certificate on iPad and iPhone
iOS and iPadOS require a few extra steps compared to Mac, but it’s straightforward once you know where to look.
AirDrop the rootCA.pem file to your iPad or iPhone. When you accept it, you’ll land in Settings under VPN & Device Management, where you’ll see a “Profile Downloaded” prompt. Tap Install and acknowledge the warning about unmanaged root certificates.

After installing the profile, you still need to explicitly enable full trust for it. Go to Settings β General β About and scroll to the very bottom. You’ll find Certificate Trust Settings there.

Inside Certificate Trust Settings, you’ll see the mkcert root CA listed. Toggle it on and confirm the warning. Apple is just reminding you that enabling a root certificate allows it to inspect all encrypted traffic, which is fine in this case since it’s your own locally-generated CA.

Once that’s done, open the UniFi app or navigate to https://ucg-fiber.home in Safari. The certificate will now show as valid and trusted.

Final Thoughts
It takes about 15 minutes to set this up the first time, and the payoff is a clean, trusted HTTPS connection to your UCG-Fiber console across all your devices. No more browser warnings, no more clicking through security exceptions.
This same approach works for any other local service you want to access over HTTPS without browser warnings. I’ve used mkcert for my Homebridge and Pi-hole setups too. Just run mkcert your-hostname.local for each one, upload or configure the cert in the respective service, and you’re done. Since the root CA is already trusted on all your devices, every new certificate you generate with it will be trusted automatically. No extra steps needed on any of your Macs, iPads, or iPhones.
If this post has been useful, support me by buying me a latte or two π
