Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] Adding a trusted local CA to Android is not honored by DDG #5497

Open
kensmith opened this issue Jan 20, 2025 · 2 comments
Open

[Bug] Adding a trusted local CA to Android is not honored by DDG #5497

kensmith opened this issue Jan 20, 2025 · 2 comments

Comments

@kensmith
Copy link

kensmith commented Jan 20, 2025

Describe the bug

DDG warns that a site may be insecure even after installing a CA certificate to Android's system level trust store.

How to Reproduce

  • Create a certificate with mkcert
  • Install as a trusted CA in Android Settings
  • Create a cert with common name = foo
  • Make sure DNS or /etc/hosts (eg. Using Virtual Hosts from Fdroid) resolves foo to the host
  • Create an HTTPS server with a mkcert certificate issued from that CA with CN = foo
  • Navigate to that server https://foo

Expected behavior

Chrome, Brave, and Firefox on the same phone all stop warning after the mkcert CA is installed in the system level trust store. I expect DDG to follow suit. This seems like a bug because the warning message claims that the certificate is not trusted by the OS when it is trusted based on being able to navigate to it in other browsers.

Image

Environment

- DDG App Version: 5.222.0 (52220000)
- Device: Pixel 8
- OS: Android 14, Build AP2A.240905.003.B1
Copy link
Contributor

Thank you for opening an Issue in our Repository.
The issue has been forwarded to the team and we'll follow up as soon as we have time to investigate.
As stated in our Contribution Guidelines, requests for feedback should be addressed via the Feedback section in the Android app.

@kensmith kensmith changed the title [Bug] <title> [Bug] Adding a trusted local CA to Android is not honored by DDG Jan 20, 2025
@karlenDimla
Copy link
Contributor

Hello! I’ve forwarded this issue internally and will let the correct team prioritise the fix. Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants