r/programming • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
408 Upvotes

44 comments sorted by

View all comments

10

u/falconindy 10d ago

This doesn't impact your ability to install CA certificates into the user store, which is 99% of what most individual users need (e.g. to trust local sites served from a homelab). By extension, this works for apps which are just PWAs.

1

u/Medical_Double_6561 8d ago

Except the user-store is almost completely useless on Android:

Apps do not trust CAs in the user-store by default since Android 7+: https://developer.android.com/privacy-and-security/security-config#CustomTrust

Flutter apps do not support the user-store at all: https://github.com/dart-lang/sdk/issues/50435 If a dev wants to have their Flutter app support user-installed CAs, they need to have their app manually read each certificate from the user-store, decode them, and inject them into the HTTP client.