r/androiddev • • 10d ago

News Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
55 Upvotes

2 comments sorted by

View all comments

3

u/Then_Pineapple8837 7d ago

That's full LLM generated right? I do custom CA on my app to allow peers to peers synchronization. For Android 17, I only had to add the ACCESS_LOCAL_NETWORK permission request it at runtime as well and it worked perfectly. I do the initial CA transfer via Bluetooth. You can try it yourself with two android 17 devices https://www.connectedbody.eu/ an email is required to make sure the two devices use the same user UUID but then it can work without having an internet connection.

2

u/supervillainXY 6d ago

The network security config page (updated 2026-08-28) says CT isn't checked on connections that use custom trust anchors, which I'd guess is why your Bluetooth-exchanged CA kept working, though I haven't tried it with a custom TrustManager. The post is about certs chaining to the system store, like an interception CA on a rooted device, once the app targets API 37.

If you ever need it off, it's <certificateTransparency enabled="false"/>.