Ø By the way, I would NOT recommend add a in-house probably unprotected CA as a trusted one. The exception is much better to deal with such cases.
If it's a work machine, then absolutely trust the in-house CA, no matter how it is managed and protected. /r$ -- Principal Security Engineer Akamai Technology Cambridge, MA