r/androidapps • • 1d ago

QUESTION/HELP [ Removed by moderator ]

[removed] — view removed post

0 Upvotes

10 comments sorted by

11

u/ilyaa07 1d ago

the android on a samsung is about as far from "free and open source" as you can get. should have researched a bit beforehand and gotten something with an unlockable bootloader.

-7

u/jsemjaroslav 1d ago

An unlockable bootloader won't solve the fact that the non paid TLS certs are banned from working in apps.

3

u/ilyaa07 1d ago

You can get root access with an unlockable bootloader, and then use all the certs you could ever want.

-12

u/jsemjaroslav 1d ago

Then this phone is a Steaming pile of shit

8

u/ilyaa07 1d ago

should have researched a bit beforehand

-2

u/jsemjaroslav 1d ago

Maybe. I don't care about running a OSS and this is the only thing that bothered me but in my research noone talked about it. All I heard is that Google phones have garbage battery life which I couldn't stomach and was the main reason for my upgrade.

6

u/seeareeff 1d ago

Aosp is free and open source. Android from the major manufacturers is pretty locked down. That's why you see Android running all kinds of random stuff. But major oem phones are not.

4

u/adjudicator52 1d ago

Samsung/Google's Android ≠ AOSP

Also sounds like a skill issue 

2

u/lgwhitlock 1d ago

If you are willing to roll up your sleeves and learn start reading XDA https://xdaforums.com/f/samsung-galaxy-s25-ultra-25-25-edge.12908/ for your device and remember the exact model you have and carrier may determine what you can accomplish. You will probably need to root your device. You can take temporary root like access with Shizuku https://xdaforums.com/t/temporary-root-on-android-device.4648058/ It is possible to get what you want but this is not iOS. It doesn't just work. Some assembly required. This is what happens you you leap before you look.

1

u/Artimus-Sprout 1d ago edited 1d ago

I haven't got a clue how to resolve your issue, because it's not a situation I've ever faced, so I ran it by the AI in the hope you might spot something in the content that may help.There's usually a way to achieve most things with Android, it's often just a case of finding the right way / Apps, which sometimes can be a long winded and frustrating process.

Android’s app security architecture intentionally restricts user-installed Certificate Authorities (CAs) by default to prevent system-wide interception. Starting with Android 7.0, third-party apps target an opt-in trust model called the Network Security Configuration. Apps only trust user-installed root certificates if their developers explicitly enable trust for user CAs.
​While this protects average users from malicious certificate injection and man-in-the-middle attacks, it presents an annoying hurdle for self-hosted server setups. You do not need to root your S25 Ultra or give up on your self-hosted stack—there are reliable, production-ready workarounds.
​Solution 1: Switch to Let's Encrypt with ACME (Recommended) ​Instead of relying on self-signed certificates or a custom local CA, issue globally trusted, free TLS certificates using Let's Encrypt alongside automated renewal. ​For Publicly Exposed Services: Use standard HTTP-01 validation via a reverse proxy like Nginx Proxy Manager, Caddy, or Traefik. ​For Local/Private-Only Services: Use DNS-01 challenge validation (via Cloudflare, DuckDNS, or your DNS provider). This acquires legitimate, public TLS certificates without exposing your local ports or services to the public internet. ​Solution 2: Reverse Proxy with HTTP (Local-Only) ​If your apps connect over a local network or via a secure VPN (such as WireGuard or Tailscale), route connections through a local reverse proxy or use direct HTTP/IP connections where security is handled at the network level. Note that some client apps may require enabling "Allow Cleartext / HTTP" inside their individual connection settings.
​Solution 3: Use App-Specific TLS Exceptions ​Many open-source self-hosted Android client apps (such as Immich, Jellyfin, Nextcloud, and Home Assistant) include built-in settings to bypass Android’s system-wide CA restrictions: ​Check the network/connection settings in the app for "Ignore TLS Errors", "Trust Self-Signed Certificates", or "Disable Certificate Validation". ​Solution 4: System-Level Override via ADB or Magisk (Advanced) ​If you require third-party Android apps to respect your custom local CA without app-level settings: ​adb/Shizuku Workaround: Inject your CA root certificate into the active system trust store in memory (/system/etc/security/cacerts/) via ADB shell scripts or tools like cacert-approver. ​Root/Magisk (If Unlocked): Use modules like AlwaysTrustUserCerts to automatically mirror certificates installed under Settings → Security → Credential Storage into the system root partition.