iOS App incompatible with LetsEncrypt
Nobody has claimed this yet.
- Dominant language
- Swift
- Stars
- 2.5k
- Forks
- 1k
- Avg merge
- 2d 18h
- Merged PRs (30d)
- 13
Description
Steps to reproduce
- Issue a certificate through Let's Encrypt
- Login to Nextcloud through iOS app
- Renew the certificate (wait for renewal or force a renewal)
Expected behaviour
This should be completely transparent for the end user.
Actual behaviour
The user is presented with a security warning stating that the certificate has changed, asking if you would like to trust this certificate.
Screenshots
https://moln.online/s/JD4zPSfkcso8fxc/preview
Logs
If applicable, you can post the iOS app or server logs (removing any sensitive information).
Reasoning or why should it be changed/implemented?
It's bad practice to train users to ignore security warnings.
Environment data
iOS version: 15.1.1
Nextcloud iOS app version: 4.1.0.17
Server operating system: Official Nextcloud docker container, nextcloud:22.
Web server: nginx
Database: PostgreSQL
Nextcloud version: 22.2.3
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the issue in the Nextcloud iOS app using a Let's Encrypt certificate, then renew the certificate and observe the login flow. The work is done when renewal remains transparent to the user and no certificate-change trust warning appears.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nginx, swift
- Domain
- mobile, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100