> Root certificates are trusted and stored locally. They’re usually shipped along the OS.

They're also shipped with the browser, as is the case with Firefox. They may also be shipped with applications (some versions of Visual Studio seem to have their own certificate store).

They're also shipped with application runtimes in the case of Java.

Thanks! Added browsers as an example.

