cryptomator / cryptomator/android
Using custom CA certificates
- Dominant language
- Kotlin
- Stars
- 1.2k
- Forks
- 216
- PR merge metrics
- No merged PRs in 30d
Description
### Please agree to the following
- [x] I have searched [existing issues](https://github.com/cryptomator/android/issues?q=) for duplicates
- [x] I agree to follow this project's [Code of Conduct](https://github.com/cryptomator/android/blob/develop/.github/CODE_OF_CONDUCT.md)
### Summary
Implementing the ability to use custom CA certificates for webdav
### Motivation
When I connect to my server over webdav-https, I am asked if I trust the certificate. I do in my case and normally the root CA, which is my custom certificate, is already stored in the android certificate manager. Thus, it seems what is missing is a way to automatically compare TLS certificates against custom root certificates.
This can for example be done by somehow accessing the system CA certificates or by for example importing a CA file when setting up a webdav connection.
### Considered Alternatives
_No response_
### Anything else?
_No response_
Contributor guide
Research direction
Start with the WebDAV-HTTPS connection setup and Android certificate manager behavior described in the issue. Compare using system CA certificates with importing a CA file, then define the supported configuration and verify that a WebDAV connection using a trusted custom root certificate succeeds without an unwanted certificate prompt.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, kotlin
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100