Skip to content

fix(android): Trust bundled ISRG Root X1 on API 25 and lower - #6227

Draft
sentry-junior[bot] wants to merge 5 commits into
mainfrom
fix/android-bundle-sentry-root-cas
Draft

sentry-junior[bot] wants to merge 5 commits into
mainfrom
fix/android-bundle-sentry-root-cas

Conversation

@sentry-junior

@sentry-junior sentry-junior Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

📜 Description

On Android API 25 and lower, the SDK now sets SentryOptions.sslSocketFactory to a new SentryRootCaSslSocketFactory. That factory trusts the system CAs plus a bundled ISRG Root X1 (Let's Encrypt), which is listed on docs.sentry.io/security-legal-pii/security/ssl.

How it works:

  • ISRG Root X1 is bundled as a PEM constant in SentryRootCertificates. A unit test checks its SHA-256 fingerprint against the docs page.
  • The system-trusted issuers and the bundled root go into a single KeyStore, which is passed to the platform's default TrustManagerFactory. Chain validation is still done by the platform. There is no custom X509TrustManager.
  • options.getSslSocketFactory() is only read by HttpConnection, so the change only applies to the SDK's own AsyncHttpTransport uploads. Other connections in the app keep using the platform defaults. No network security config is involved.
  • The SSLContext is built lazily on first use, on the transport thread. If building it fails, we log an error and fall back to the default factory.
  • If the user already set a custom sslSocketFactory, it is kept.
  • All new classes are package-private, so there are no public API changes.

💡 Motivation and Context

Sentry is moving its TLS certificates from DigiCert to Let's Encrypt and Google Trust Services (announcement). Here is which roots each Android version ships, based on the AOSP CA store:

  • ISRG Root X1 was only added in Android 7.1 (API 25). Let's Encrypt's default chains (RSA and ECDSA) all end at X1, so API 21–24 can't validate them without this change. The factory also applies on API 25 to cover vendor builds that lack the root.
  • GTS: Google's default chain includes GTS Root R1 cross-signed by GlobalSign Root CA, which Android 5+ already trusts. That cross-sign expires on 2028-01-28, after which API ≤28 will need the GTS roots. This is left for a follow-up and marked with a TODO(2028-01-28) in SentryRootCertificates.
  • DigiCert Global Root CA and G2 are already in every supported API level.
  • ISRG Root X2 isn't needed, because Sentry will serve Let's Encrypt's default chain, which ends at X1.

Known limitation: this only helps apps that update to an SDK version containing this fix.

💚 How did you test it?

Unit tests:

  • SentryRootCaSslSocketFactoryTest: checks the bundled root's fingerprint, that the merged trust store keeps every system-trusted CA, and that the delegate is created lazily and only once.
  • AndroidOptionsInitializerTest: checks that the factory is set on API 25, not set on API 26, and that a user-provided factory is kept.

This hasn't been verified on a real API 21–25 device or emulator against a Let's Encrypt endpoint yet.

📝 Checklist

  • I added GH Issue ID & Linear ID
  • I added tests to verify the changes.
  • No new PII added or SDK only sends newly added PII if sendDefaultPII is enabled.
  • I updated the docs if needed.
  • I updated the wizard if needed.
  • Review from the native team if needed.
  • No breaking change or entry added to the changelog.
  • No breaking change for hybrid SDKs or communicated to hybrid SDKs.
  • Public API changes reviewed by another Mobile SDK team member or implemented according to the develop docs spec.

🔮 Next steps

  • Do a manual check on an API 21–25 emulator against an ISRG-signed endpoint.
  • Before 2028-01-28, revisit bundling the GTS roots for API ≤28 (see the TODO in SentryRootCertificates).

via roman.

--

View Junior Session [Sentry]

sentry-junior Bot and others added 2 commits October 6, 2026 07:53
Co-Authored-By: Markus Hintersteiner <markus.hintersteiner@sentry.io>
Co-Authored-By: Markus Hintersteiner <markus.hintersteiner@sentry.io>
@sentry

sentry Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

📲 Install Builds

Android

🔗 App Name App ID Version Configuration
SDK Size io.sentry.tests.size 8.59.0 (1) release

⚙️ sentry-android Build Distribution Settings

sentry-junior Bot and others added 2 commits October 6, 2026 09:00
Co-Authored-By: Roman Zavarnitsyn <roman.zavarnitsyn@sentry.io>
Co-Authored-By: Roman Zavarnitsyn <roman.zavarnitsyn@sentry.io>
@sentry-junior sentry-junior Bot changed the title fix(android): Trust bundled Sentry root CAs on API 25 and lower fix(android): Trust bundled ISRG Root X1 on API 25 and lower Oct 6, 2026

@runningcode runningcode left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gave it a quick look while it is still in draft mode. feel free to re-ask for a review once it is out of draft

Comment thread CHANGELOG.md Outdated
- Mark SentryRootCaSslSocketFactory and SentryRootCertificates as @ApiStatus.Internal
- Use StandardCharsets.UTF_8 instead of suppressing CharsetObjectCanBeUsed (minSdk 21)
- Import Certificate in the test
- Rewrite the changelog entry and link the TLS CA change announcement

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant