ublproxy Setup
Get your device connected in a few steps.
Install Certificate
Your device must trust the ublproxy CA certificate before the proxy can filter HTTPS traffic. Without it, every HTTPS request through the proxy will fail with a certificate error.
This profile installs the CA certificate and configures proxy settings in one step.
- Download the profile above
- iOS: Go to Settings → General → VPN & Device Management → tap the profile → Install
- iOS: Go to Settings → General → About → Certificate Trust Settings → enable full trust for ublproxy CA
- macOS: Open the downloaded file → Keychain Access will prompt to install
- macOS: Open the .crt file → add to System keychain → find ublproxy CA → set Trust to Always Trust
- iOS: Download .crt → Settings → General → VPN & Device Management → install → then enable full trust under Certificate Trust Settings
- Restart your browser after installing
- Download the certificate above
- Go to Settings → Security → Encryption & Credentials → Install a certificate → CA certificate
- Select the downloaded ublproxy-ca.crt file and confirm
Menu paths vary by manufacturer (Samsung, Pixel, etc.).
- Download and double-click the certificate
- Click Install Certificate
- Select Local Machine, then Place all certificates in the following store
- Choose Trusted Root Certification Authorities and finish the wizard
- Restart your browser
- Copy the certificate:
sudo cp ublproxy-ca.crt /usr/local/share/ca-certificates/ - Update the trust store:
sudo update-ca-certificates - Restart your browser
Firefox uses its own certificate store, separate from your OS. You may need to install the certificate here in addition to your OS trust store.
Download CA Certificate- Open Settings → Privacy & Security → Certificates → View Certificates
- Click Import and select the downloaded .crt file
- Check Trust this CA to identify websites and confirm
- Restart Firefox
Scan to open this page on your phone:
Configure Proxy
Use the automatic proxy configuration file (PAC) to route traffic through ublproxy.
Desktop
PAC URL:
- Open System Settings → Network → Wi-Fi → Details → Proxies
- Enable Automatic Proxy Configuration
- Enter the PAC URL shown above
- Open Settings → Network & Internet → Proxy
- Under Automatic proxy setup, enable Use setup script
- Enter the PAC URL shown above
- Configure your browser's proxy settings to use the PAC URL above
- Or launch Chromium with:
- Open Settings → General → Network Settings → Settings…
- Select Automatic proxy configuration URL
- Enter the PAC URL shown above
- Click OK
Mobile
Mobile devices use a separate PAC URL (plain HTTP proxy):
- Go to Settings → Wi-Fi
- Tap the info button on your connected network
- Scroll to Configure Proxy and select Automatic
- Enter the mobile PAC URL shown above
- Go to Settings → Wi-Fi
- Tap the gear icon on your connected network
- Set Proxy to Proxy Auto-Config
- Enter the mobile PAC URL shown above
The desktop PAC routes traffic through the encrypted HTTPS proxy. The mobile PAC uses a plain HTTP proxy because iOS and Android do not support HTTPS proxy connections. HTTPS traffic is still filtered via MITM.
Verify Setup
Check that the CA certificate is installed and trusted by your browser.
Setup Complete
Your device is ready to use ublproxy for ad-free browsing.
Register a passkey on the management portal to create custom blocking rules and manage your blocklist subscriptions.