fix(android): Trust bundled ISRG Root X1 on API 25 and lower - #6227
Draft
sentry-junior[bot] wants to merge 5 commits into
Draft
sentry-junior[bot] wants to merge 5 commits into
sentry-junior[bot] wants to merge 5 commits into
Conversation
Co-Authored-By: Markus Hintersteiner <markus.hintersteiner@sentry.io>
📲 Install BuildsAndroid
|
Co-Authored-By: Roman Zavarnitsyn <roman.zavarnitsyn@sentry.io>
Co-Authored-By: Roman Zavarnitsyn <roman.zavarnitsyn@sentry.io>
runningcode
reviewed
Oct 6, 2026
runningcode
left a comment
Contributor
There was a problem hiding this comment.
gave it a quick look while it is still in draft mode. feel free to re-ask for a review once it is out of draft
- Mark SentryRootCaSslSocketFactory and SentryRootCertificates as @ApiStatus.Internal - Use StandardCharsets.UTF_8 instead of suppressing CharsetObjectCanBeUsed (minSdk 21) - Import Certificate in the test - Rewrite the changelog entry and link the TLS CA change announcement
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📜 Description
On Android API 25 and lower, the SDK now sets
SentryOptions.sslSocketFactoryto a newSentryRootCaSslSocketFactory. That factory trusts the system CAs plus a bundled ISRG Root X1 (Let's Encrypt), which is listed on docs.sentry.io/security-legal-pii/security/ssl.How it works:
SentryRootCertificates. A unit test checks its SHA-256 fingerprint against the docs page.KeyStore, which is passed to the platform's defaultTrustManagerFactory. Chain validation is still done by the platform. There is no customX509TrustManager.options.getSslSocketFactory()is only read byHttpConnection, so the change only applies to the SDK's ownAsyncHttpTransportuploads. Other connections in the app keep using the platform defaults. No network security config is involved.SSLContextis built lazily on first use, on the transport thread. If building it fails, we log an error and fall back to the default factory.sslSocketFactory, it is kept.💡 Motivation and Context
Sentry is moving its TLS certificates from DigiCert to Let's Encrypt and Google Trust Services (announcement). Here is which roots each Android version ships, based on the AOSP CA store:
TODO(2028-01-28)inSentryRootCertificates.Known limitation: this only helps apps that update to an SDK version containing this fix.
💚 How did you test it?
Unit tests:
SentryRootCaSslSocketFactoryTest: checks the bundled root's fingerprint, that the merged trust store keeps every system-trusted CA, and that the delegate is created lazily and only once.AndroidOptionsInitializerTest: checks that the factory is set on API 25, not set on API 26, and that a user-provided factory is kept.This hasn't been verified on a real API 21–25 device or emulator against a Let's Encrypt endpoint yet.
📝 Checklist
sendDefaultPIIis enabled.🔮 Next steps
SentryRootCertificates).via roman.
--
View Junior Session [Sentry]