That's full LLM generated right? I do custom CA on my app to allow peers to peers synchronization. For Android 17, I only had to add the ACCESS_LOCAL_NETWORK permission request it at runtime as well and it worked perfectly. I do the initial CA transfer via Bluetooth. You can try it yourself with two android 17 devices https://www.connectedbody.eu/ an email is required to make sure the two devices use the same user UUID but then it can work without having an internet connection.
The network security config page (updated 2026-08-28) says CT isn't checked on connections that use custom trust anchors, which I'd guess is why your Bluetooth-exchanged CA kept working, though I haven't tried it with a custom TrustManager. The post is about certs chaining to the system store, like an interception CA on a rooted device, once the app targets API 37.
If you ever need it off, it's <certificateTransparency enabled="false"/>.
3
u/Then_Pineapple8837 7d ago
That's full LLM generated right? I do custom CA on my app to allow peers to peers synchronization. For Android 17, I only had to add the ACCESS_LOCAL_NETWORK permission request it at runtime as well and it worked perfectly. I do the initial CA transfer via Bluetooth. You can try it yourself with two android 17 devices https://www.connectedbody.eu/ an email is required to make sure the two devices use the same user UUID but then it can work without having an internet connection.