PhilippC / PhilippC/keepass2android

[BUG] server certificate validation failed android trust anchor for certificate...

Open
#2,779 4 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
C#
Stars
6.2k
Forks
478
Avg merge
1h 4m
Merged PRs (30d)
2

Description

Checks
  • I have read the FAQ section, searched the open issues, and still think this is a new bug.
Describe the bug you encountered:

Hi,

I'm having an issue with a self signed CA certificate in keepass2android. I get the error: server certificate validation failed android trust anchor for certificate... my last certificate was working ok with keepass2android. Just had to add it to the android certificate store. But I've had to mint a new one (using the same method as the last one) and keepass2android is being pretty stubborn.

Other apps can access/see the new certificate from the certificate store and recognise it as valid. For example, I can set firefox android to use 3rd party certificates from the ca store and the connection is recognised as valid and secure.

Although I can open, sync and add entries fine in keepass2android, the error seems to be the only issue.

My suspicion is it's still holding onto the old one somehow. I've tried emptying the cache files etc, uninstalling/reinstalling so far to no avail.

Describe what you expected to happen:

See my certificate as valid.

What version of Keepass2Android are you using?

I've tried a few but currently 1.11-r0.

Which version of Android are you on?

12

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the certificate validation failure on Android 12 with Keepass2Android 1.11-r0, using the newly minted self-signed CA and certificate store. Compare the behavior with the previously working certificate and other Android apps; done means the new certificate is recognized as valid and syncing works without the trust-anchor error.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, csharp
Domain
mobile-dev, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.