Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow but pin self signed certificates / CACert #42

Closed
t2d opened this issue Jun 13, 2013 · 5 comments
Closed

Allow but pin self signed certificates / CACert #42

t2d opened this issue Jun 13, 2013 · 5 comments

Comments

@t2d
Copy link

t2d commented Jun 13, 2013

My owncloud uses a certificate by CACert. (I know I could import their cert on a rooted phone but I may not have one).
At the moment my only option to connect is to "Allow any SSL Certificate".
Could you add an option to acknowledge or deny the certificate when it changes? Atm I would send my credentials to anyone doing MitM.

Would be great!

@David-Development
Copy link
Member

Yes I've talked with the News App developer already about this issue. I'm going to improve it in a future version but first I've to fix some other issues which are more important atm.

@David-Development
Copy link
Member

I think since 0.3.4 --> STRICT_HOSTNAME_VERIFICATION it's not possible any longer.. isn't it ?

@t2d
Copy link
Author

t2d commented Jun 25, 2013

I think this is still the same issue if an MitM sends me a false certificate with the right hostname.

@t2d
Copy link
Author

t2d commented Jul 3, 2013

you should have a look at this: https://github.com/moxie0/AndroidPinning

@David-Development
Copy link
Member

Thank you for the information, I'm going to read it. But atm I've not as much time as I like to have

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants