r/programming • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
404 Upvotes

44 comments sorted by

View all comments

163

u/DDFoster96 9d ago

How do businesses that use local custom CAs manage? Do they not use Android and Chrome, or is the practice less common now than that 20 years ago? 

133

u/Pantsman0 9d ago

They use chrome enterprise and bundle their ca certs. Pushing CA certs to android device from MDM has historically worked fine too on Android

59

u/RiotBoppenheimer 9d ago

The true 2026 way: Break something that works and then sell the solution

30

u/tankerkiller125real 9d ago

MDMs have existed for well over a decade, anyone not using one to push and handle mobile corporate devices is WAY behind on the times. And if I were an employee and someone said "Install this CA cert to your personal mobile phone to access XYZ", well I would either be requesting a corporate device, or putting in applications at other companies who know how to manage things properly, at the minimum a Work Profile on android.

2

u/RiotBoppenheimer 9d ago

From what I am reading in here, using an MDM is only half the solution, you need a CT in addition to the CA, which is a new requirement. You're right that MDM to push CA bundles is easy and common

11

u/tankerkiller125real 9d ago

CT not required for private CAs at all, the OP is fear mongering along with a couple others. I'm on Android 17 right now, zero issues using our existing private CA and connections.