How to check certificates on Windows 10: a detailed step-by-step guide

To check certificates on Windows 10, press Windows + R, type certmgr.msc for your own user certificates or certlm.msc for the computer's certificates, and press Enter.

This guide covers seven ways to view certificates, the stores they live in, how to judge whether one is healthy, and what to do when one is expired or untrusted.

Method 1: Check Certificates with Certificate Manager

Certificate Manager is built into Windows 10. certmgr.msc opens the current user's stores, and certlm.msc opens the local computer's stores.

  1. Press Windows + R to open Run.
  2. Type certmgr.msc and press Enter. For computer certificates, type certlm.msc instead and approve the User Account Control prompt.
  3. In the left pane, expand Certificates – Current User or Certificates – Local Computer.
  4. Expand a store such as Personal and select Certificates.
  5. Read the Issued To, Issued By and Expiration Date columns in the right pane.
  6. Double-click a certificate to open its details.

What Certificates Are Used for in Windows 10

A digital certificate binds a name, such as a website, person or software publisher, to a public key, and a trusted authority vouches for it. Windows checks certificates every time you open an HTTPS site, run signed software or sign in with some work accounts.

Use Where you meet it
Secure websites (HTTPS) The padlock in Edge or Chrome; the site's certificate proves its identity
Code signing The publisher name shown when you install or run a signed program
Driver signing Windows checks driver signatures against trusted root certificates during installation
Client authentication Work Wi-Fi, VPN and some company sign-ins use a certificate in your Personal store
Email signing and encryption Signed or encrypted messages use a personal certificate
Trust anchors Root certificates of every authority Windows trusts sit in Trusted Root Certification Authorities

Before You Start: User Certificates vs Computer Certificates

Windows keeps two main sets of stores. Pick the right one before you search, or the certificate you want can look missing.

You want to check Open this Why
Certificates installed for your account only certmgr.msc (Current User) Stored under HKEY_CURRENT_USER and visible only to you
Certificates used by the whole PC, services or IIS certlm.msc (Local Computer) Stored under HKEY_LOCAL_MACHINE and shared by every user
A service's own certificates MMC with Service account Each service can have its own store
A website's certificate The browser's address bar Site certificates are checked live, not stored in Windows
A file before you install it Double-click the file or run certutil -dump Nothing is added to a store

Current user stores, except Personal, inherit the local computer's stores. A root certificate added for the computer also shows in every user's Trusted Root Certification Authorities store. You need administrator rights to view or change local computer certificates.

Method 2: Check Computer Certificates with MMC

The Microsoft Management Console route reaches the same stores and can also open a service account's certificates. Save the console to reopen it in one click later.

  1. Press Windows + R, type mmc and press Enter, then select Yes at the User Account Control prompt.
  2. Select File > Add/Remove Snap-in.
  3. Under Available snap-ins, choose Certificates and select Add.
  4. Select Computer account and then Next. Choose My user account or Service account for other stores.
  5. Leave Local computer selected and select Finish, then OK.
  6. Expand Console Root > Certificates (Local Computer), then open Personal, Trusted Root Certification Authorities or Intermediate Certification Authorities.
  7. Optional: select File > Save As to keep the console for later use.
Add or Remove Snap-ins dialog with Certificates selected and Add button highlighted
Select Certificates in the list, then select Add to open the account choice for the console. (Image: Microsoft)

Method 3: Check a Website Certificate in Microsoft Edge or Google Chrome

Both browsers show a site's security status next to the address. The developer tools give a full certificate view in either browser.

  1. Open the site and look at the icon to the left of the web address: a lock means a secure connection, while Not secure or a warning icon means a problem.
  2. Select the icon to see the site's connection summary.
  3. For the full certificate, press Ctrl + Shift + I to open DevTools.
  4. Select the Security tab; if it is not visible, find it under More Tools.
  5. In Security Overview, select View certificate to open the Certificate Viewer.
  6. Check that the name listed matches the site's domain, and check the validity dates.

A domain match matters most. A certificate for www.example.com on a page at a different domain triggers a warning even when the certificate itself is in date.

Edge DevTools Security tab showing a secure page with a View certificate button
In the Security overview, the View certificate button opens the Certificate Viewer for the site. (Image: Microsoft)

Method 4: Check Certificates with PowerShell

PowerShell exposes every store as the Cert: drive. Run PowerShell as administrator to read LocalMachine stores.

Get-ChildItem Cert:\CurrentUser\My | Format-List Subject, Issuer, NotAfter, Thumbprint, HasPrivateKey

Lists every certificate in your Personal store with its subject, issuer, expiry date (NotAfter), thumbprint and whether its private key is present. Replace CurrentUser\My with LocalMachine\My for the computer's Personal store, or LocalMachine\Root for trusted roots. To find certificates that expire within 30 days, run Get-ChildItem Cert:\LocalMachine\My | Where-Object { $_.NotAfter -lt (Get-Date).AddDays(30) }.

You should see: A block of properties appears for each certificate. No output means the store is empty or the filter matched nothing.

PowerShell 7.1 and later also accept -ExpiringInDays, -DnsName and -CodeSigningCert on the Cert: drive. For example, Get-ChildItem -Path Cert:\* -Recurse -ExpiringInDays 0 lists certificates in every store that have already expired.

Method 5: Check Certificates with Certutil

certutil ships with Windows and works in Command Prompt. It reads the local machine stores by default; add -user for your own stores.

certutil -store My

Dumps every certificate in the local computer's Personal store, including serial number, issuer, NotBefore and NotAfter dates, subject and hash. Use certutil -user -store My for your own Personal store, or certutil -store Root for trusted root certificates. Run Command Prompt as administrator for machine stores.

You should see: Each certificate is listed with an index number, and the output ends with CertUtil: -store command completed successfully.

Microsoft notes that -store slows down on stores holding more than 10 certificates, and recommends PowerShell when you only need one certificate type.

Method 6: Check a Certificate File Before Installing It

Inspect a .cer or .crt file before you import it, so you know who issued it and what it is for.

  1. Open File Explorer and go to the folder holding the certificate file.
  2. Double-click the file to open the Certificate window without installing it.
  3. On the General tab, read Issued to, Issued by and the Valid from dates.
  4. Open the Details tab to check the subject, the key usage and the thumbprint against the one the sender gave you.
  5. Open the Certification Path tab to see the chain up to its root.
  6. Close the window without selecting Install Certificate if anything does not match.

To read the same file in Command Prompt, run certutil -dump C:\path\to\file.cer. To test its chain, run certutil -verify C:\path\to\file.cer.

Method 7: Check a Software Publisher Certificate

Signed programs and scripts carry an Authenticode signature from the publisher's code-signing certificate. Check it before running a file from an unfamiliar source.

  1. Right-click the .exe, .msi or script file and select Properties.
  2. Open the Digital Signatures tab; if there is no such tab, the file is not signed.
  3. Select the signature in the list and select Details.
  4. Confirm the signer name is the publisher you expect.
  5. Select View Certificate to see the issuer and validity dates.
  6. In PowerShell, run Get-AuthenticodeSignature -FilePath "C:\path\to\file.exe" and confirm the Status column reads Valid.

An unsigned file returns blank signature fields in PowerShell. If a file is both embedded-signed and catalog-signed, PowerShell reports the Windows catalog signature.

Common Certificate Stores in Windows 10

Each store holds one kind of certificate. The store name in brackets is the one PowerShell and certutil use.

Store in Certificate Manager Short name What it holds
Personal My Certificates with private keys issued to you or this computer
Trusted Root Certification Authorities Root Root certificates of every authority Windows trusts
Intermediate Certification Authorities CA Intermediate certificates that link site and app certificates to a root
Trusted Publishers TrustedPublisher Publishers whose signed software is trusted
Untrusted Certificates Disallowed Certificates Windows has been told to reject
Enterprise Trust Trust Certificate trust lists set by an organisation

Current user stores live under HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates, and local computer stores under HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates. Use the tools above instead of editing these keys.

How to Tell If a Certificate Is Healthy

Open the certificate by double-clicking it in Certificate Manager, then run through these checks.

  1. On the General tab, confirm today's date falls between the Valid from dates.
  2. Confirm Issued to matches the site, user, computer or publisher you expect.
  3. Look for the line saying you have a private key that corresponds to the certificate, if you need it for sign-in or signing.
  4. On the Certification Path tab, confirm the chain ends at a trusted root and Certificate status reports that the certificate is OK.
  5. On the Details tab, check Enhanced Key Usage lists the purpose you need, such as server or client authentication.

Troubleshooting Common Certificate Problems

The certificate you installed does not appear

It went into the other location: your user stores instead of the computer's, or the reverse.

  1. Open both certmgr.msc and certlm.msc.
  2. Check Personal, Intermediate Certification Authorities and Trusted Root Certification Authorities in each.
  3. Or search every store at once with Get-ChildItem -Path Cert:\ -Recurse in an administrator PowerShell window.

A certificate shows as expired

Its NotAfter date has passed, and Windows no longer accepts it.

  1. Note the issuer on the General tab.
  2. Request a renewed certificate from the issuer, your IT team or the site owner.
  3. Install the renewed certificate, then confirm the new expiry date in Certificate Manager.

Certificate status says the chain cannot be verified

An intermediate or root certificate in the chain is missing from the stores.

  1. Open the Certification Path tab and find the certificate marked with an error.
  2. Get the missing intermediate certificate from the issuing authority's own site.
  3. Import it into Intermediate Certification Authorities, then reopen the certificate to recheck.

Browser warns that the site's certificate is not valid

The name does not match the domain, the certificate has expired, or the PC clock is wrong.

  1. Check that your PC's date and time are correct.
  2. Open DevTools > Security > View certificate and compare the listed names with the address.
  3. If the certificate is wrong, leave the site and contact its owner instead of bypassing the warning.

Certificate Manager says you lack permission

Local computer stores need administrator rights.

  1. Sign in with an administrator account.
  2. Run certlm.msc or PowerShell as administrator.
  3. Use certmgr.msc if you only need your own certificates.
Certificate Viewer General tab listing Issued To and Issued By details
Compare the Issued To name here with the address in the browser when a site certificate warning appears. (Image: Microsoft)

Safety Tips When Managing Certificates

Tip Why it matters
Never delete a root certificate you do not recognise without checking first Windows and apps rely on root certificates; removing one can break sites, updates or drivers
Export a certificate before deleting it An exported copy lets you restore it if something stops working
Import root certificates only from your organisation or a known authority A rogue root lets an attacker impersonate any website
Protect exported .pfx files with a strong password They contain the private key
Do not click through browser certificate warnings on sign-in or payment pages The warning is often the only sign of an intercepted connection
Use certmgr.msc unless you need machine certificates It avoids accidental changes that affect every user

Frequently Asked Questions

Where are certificates stored on Windows 10?

User certificates are stored under HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates, and computer certificates under HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates. View them with certmgr.msc and certlm.msc rather than in the registry.

How do I see the certificates installed on Windows?

Press Windows + R, type certmgr.msc and press Enter to see your user certificates. Type certlm.msc instead for certificates installed for the whole computer. Expand a store such as Personal to list them.

How do I check certificates in Windows Server?

Use the same tools: certlm.msc for the server's own certificates, the MMC Certificates snap-in, certutil -store My, or Get-ChildItem Cert:\LocalMachine\My in PowerShell. Run each as administrator.

How do I find certificates that are about to expire?

In PowerShell, run Get-ChildItem Cert:\LocalMachine\My | Where-Object { $_.NotAfter -lt (Get-Date).AddDays(30) }. In Certificate Manager, sort the Expiration Date column instead.

What is the difference between certmgr.msc and certlm.msc?

certmgr.msc opens the current user's certificate stores and needs no admin rights. certlm.msc opens the local computer's stores, which every user and service shares, and needs administrator rights.

How do I access certificates on Windows 10 from Command Prompt?

Run certutil -store My for the computer's Personal store or certutil -user -store My for your own. Swap My for Root or CA to list trusted root or intermediate certificates.

How do I check my Microsoft certifications rather than PC certificates?

Microsoft exam certifications are a different thing. Sign in to Microsoft Learn, open your Certification Dashboard, and select View Certificates to preview or download them, or View Transcript to share your record.

Is it safe to delete old certificates?

Expired personal certificates are usually safe to remove, but export them first. Leave root and intermediate certificates alone unless your IT team or the issuer tells you to remove a specific one.

Which tool to keep using

Use certmgr.msc and certlm.msc for a quick look, and PowerShell's Cert: drive when you need to search or audit expiry dates across stores. The snap-ins show every detail with no typing, while PowerShell filters by expiry or purpose in one line and works the same on Windows Server. If you are unsure which Windows release you run, check your Windows version first, since these tools behave the same on Windows 10 and 11.

Philip Celasco

Philip is a Texas-based technology writer and IT administrator at Techdows.com with more than 10 years of experience creating practical content for everyday users and professionals. He specializes in web browsers, particularly Chromium-based platforms such as Google Chrome, Microsoft Edge, Brave, and Opera. Through his work as an IT administrator, Philip has hands-on experience managing devices, configuring browser policies, troubleshooting software and network issues, and helping people resolve problems that affect productivity and security. His articles are based on practical testing and real-world technical experience. He covers browser settings, extensions, performance problems, privacy controls, security features, and Windows troubleshooting. Outside work, Philip enjoys the quieter side of life in Texas and stepping away from the screen when he can. He has two kids, two cats and loves to play golf with his mother during the weekends.

Leave a Reply

Your email address will not be published. Required fields are marked *