Welcome to the Clan MacKinnon HomeLab
Set up this device once, then use the private family media services without certificate warnings.
Download the HomeLab certificate
This certificate tells your device that the private HomeLab websites are trusted.
Downloading the certificate does not install or trust it. On iPhone and iPad, iOS registers it as a downloaded profile so you can install it later from Settings. Choose your device below and complete every step.
Choose your device
Select one option. Its complete setup guide will open underneath.
Windows PC
- Open your Downloads folder.
- Double-click rootCA.crt.
- Select Install Certificate.
- Select Current User, then select Next.
- Select Place all certificates in the following store.
- Select Browse, choose Trusted Root Certification Authorities, then select OK.
- Select Next, then Finish.
- Approve the security message by selecting Yes.
- Close and reopen your web browser.
Mac
- Open Keychain Access using Spotlight search.
- In the sidebar, select the System keychain.
- Drag rootCA.crt from Downloads into Keychain Access.
- Enter an administrator username and password if prompted.
- Select Certificates, then double-click the newly added HomeLab certificate.
- Expand Trust.
- Set When using this certificate to Always Trust.
- Close the certificate window and approve the change if prompted.
- Close and reopen your web browser.
iPhone or iPad
iPhone and iPad setup
You have already downloaded the HomeLab certificate in Step 1. Now connect with WireGuard, then install and trust that downloaded certificate profile.
1Install WireGuard
Install the official WireGuard app from the App Store.
After installation, open WireGuard. You should see an empty tunnel list with a + button in the top-right corner.
2Download the Home Pi VPN configuration
Tap the button below and save the configuration in the iPhone or iPad Files app.
Remember: the file will normally appear in Files → Downloads unless you choose another location.
3Import the VPN configuration
WireGuard → + → Create from file or archiveBrowse to the location where you saved Home-Pi-VPN.conf, then select it.
Choose this option: “Create from file or archive” — not QR code or scratch.
4Allow and connect the VPN
When iOS asks whether WireGuard may add VPN configurations, tap Allow and authenticate if requested.
In WireGuard, turn on the switch beside Home Pi VPN.
Check: the tunnel switch should be on and iOS should show the VPN connection as active.
Do not use “Add VPN Configuration” in iPhone Settings. Home Pi VPN is managed by the WireGuard app.
5Install the certificate already downloaded in Step 1
Open the Settings app. iOS should retain the downloaded certificate as a pending profile; the Join page cannot directly reopen files or Settings because iOS prevents websites from accessing them.
Settings → Profile DownloadedIf Profile Downloaded is not shown near the top of Settings, use:
Settings → General → VPN & Device ManagementSelect the downloaded HomeLab certificate profile, tap Install in the top-right corner, enter your passcode and complete the prompts.
6Enable full trust for the certificate
Installing the profile is not enough. You must also enable full trust.
Settings → General → About → Certificate Trust SettingsUnder Enable Full Trust for Root Certificates, turn on:
mkcert neil@pi1-apps-vpn (Neil MacKinnon)
Confirm the warning.
7Finish and test
Completely close Safari, reopen it and keep Home Pi VPN connected whenever you are away from home.
Setup complete. You can now open the private HomeLab websites without certificate warnings.
Important: iOS may remove a downloaded profile if it is not installed promptly. If Profile Downloaded disappears, return to Step 1 in Safari and download the certificate again. Stolen Device Protection may delay profile installation when you are away from a familiar location.
Open the HomeLab
Once your certificate is installed and trusted, open the private family services.
Having trouble?
Make sure you are connected to the home Wi-Fi or to Home Pi VPN. On iPhone and iPad, also confirm that the HomeLab certificate profile is installed and full trust is enabled.
Android instructions will be added after they are validated on an actual device.