Skip to content

Use /system/etc/security/cacerts on Android - #51

Open
tyilo wants to merge 1 commit into
rustls:mainfrom
tyilo:android-cert-dir
Open

Use /system/etc/security/cacerts on Android#51
tyilo wants to merge 1 commit into
rustls:mainfrom
tyilo:android-cert-dir

Conversation

@tyilo

@tyilo tyilo commented Jul 28, 2026

Copy link
Copy Markdown

Running the print-trust-anchors example from rustls-native-certs results in an empty list without this change.

Output with the change:

C=US, O=Amazon, CN=Amazon Root CA 3
OU=GlobalSign ECC Root CA - R4, O=GlobalSign, CN=GlobalSign
C=US, O=Amazon, CN=Amazon Root CA 4
C=US, O=Certainly, CN=Certainly Root E1
C=US, O=AffirmTrust, CN=AffirmTrust Premium ECC
C=US, O=Google Trust Services LLC, CN=GTS Root R3
C=US, O=Google Trust Services LLC, CN=GTS Root R4
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Root E46
C=CN, O=iTrusChina Co.,Ltd., CN=vTrus ECC Root CA
CN=Atos TrustedRoot Root CA ECC TLS 2021, O=Atos, C=DE
C=US, O=DigiCert, Inc., CN=DigiCert TLS ECC P384 Root G5
C=US, O=Internet Security Research Group, CN=ISRG Root X2
C=US, O=CommScope, CN=CommScope Public Trust ECC Root-02
C=US, O=CommScope, CN=CommScope Public Trust ECC Root-01
OU=GlobalSign ECC Root CA - R5, O=GlobalSign, CN=GlobalSign
C=JP, O=Cybertrust Japan Co., Ltd., CN=SecureSign Root CA15
C=CN, O=BEIJING CERTIFICATE AUTHORITY, CN=BJCA Global Root CA2
C=US, OU=emSign PKI, O=eMudhra Inc, CN=emSign ECC Root CA - C3
C=CN, O=TrustAsia Technologies, Inc., CN=TrustAsia TLS ECC Root CA
C=CH, O=OISTE Foundation, CN=OISTE Server Root ECC G1
C=JP, O=SECOM Trust Systems CO.,LTD., CN=Security Communication ECC RootCA1
C=US, O=SSL Corporation, CN=SSL.com TLS ECC Root CA 2022
C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication Root E46
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
C=HU, L=Budapest, O=Microsec Ltd., OID(2.5.4.97)=VATHU-23584497, CN=e-Szigno Root CA 2017
C=DE, O=Deutsche Telekom Security GmbH, CN=Telekom Security TLS ECC Root 2020
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root G3
C=IN, OU=emSign PKI, O=eMudhra Technologies Limited, CN=emSign ECC Root CA - G3
C=GR, O=Hellenic Academic and Research Institutions CA, CN=HARICA TLS ECC Root CA 2021
C=CN, O=TrustAsia Technologies, Inc., CN=TrustAsia Global Root CA G4
C=US, O=Microsoft Corporation, CN=Microsoft ECC Root Certificate Authority 2017
C=US, ST=Illinois, L=Chicago, O=Trustwave Holdings, Inc., CN=Trustwave Global ECC P256 Certification Authority
C=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, CN=Certum EC-384 CA
C=CH, O=WISeKey, OU=OISTE Foundation Endorsed, CN=OISTE WISeKey Global Root GC CA
C=ES, O=FNMT-RCM, OU=Ceres, OID(2.5.4.97)=VATES-Q2826004J, CN=AC RAIZ FNMT-RCM SERVIDORES SEGUROS
C=ES, O=Firmaprofesional SA, OID(2.5.4.97)=VATES-A62634068, CN=FIRMAPROFESIONAL CA ROOT-A WEB
C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO ECC Certification Authority
C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com Root Certification Authority ECC
C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com EV Root Certification Authority ECC
C=US, ST=Illinois, L=Chicago, O=Trustwave Holdings, Inc., CN=Trustwave Global ECC P384 Certification Authority
C=GR, L=Athens, O=Hellenic Academic and Research Institutions Cert. Authority, CN=Hellenic Academic and Research Institutions ECC RootCA 2015
C=DE, O=D-Trust GmbH, CN=D-TRUST EV Root CA 1 2020
C=DE, O=D-Trust GmbH, CN=D-TRUST BR Root CA 1 2020
C=RO, O=certSIGN, OU=certSIGN ROOT CA
C=US, O=Amazon, CN=Amazon Root CA 1
C=US, O=AffirmTrust, CN=AffirmTrust Commercial
C=US, O=AffirmTrust, CN=AffirmTrust Networking
OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
C=PL, O=Krajowa Izba Rozliczeniowa S.A., CN=SZAFIR ROOT CA2
C=JP, O=Cybertrust Japan Co., Ltd., CN=SecureSign Root CA12
C=US, OU=emSign PKI, O=eMudhra Inc, CN=emSign Root CA - C1
C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
CN=Atos TrustedRoot 2011, O=Atos, C=DE
C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
C=IN, OU=emSign PKI, O=eMudhra Technologies Limited, CN=emSign Root CA - G1
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root G2
C=FR, O=Dhimyotis, CN=Certigna
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
C=CH, O=WISeKey, OU=OISTE Foundation Endorsed, CN=OISTE WISeKey Global Root GB CA
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
C=US, O=SecureTrust Corporation, CN=SecureTrust CA
C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
C=US, O=SecureTrust Corporation, CN=Secure Global CA
C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 2
C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 3
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2
C=HU, L=Budapest, O=Microsec Ltd., CN=Microsec e-Szigno Root CA 2009, Email=info@e-szigno.hu
C=HU, L=Budapest, O=NetLock Kft., OU=Tanúsítványkiadók (Certification Services), CN=NetLock Arany (Class Gold) Főtanúsítvány
C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO Certification Authority
C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 EV 2009
C=TR, L=Gebze - Kocaeli, O=Turkiye Bilimsel ve Teknolojik Arastirma Kurumu - TUBITAK, OU=Kamu Sertifikasyon Merkezi - Kamu SM, CN=TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1
O=TeliaSonera, CN=TeliaSonera Root CA v1
C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Global Root CA
C=US, O=Amazon, CN=Amazon Root CA 2
C=US, O=AffirmTrust, CN=AffirmTrust Premium
C=CN, O=UniTrust, CN=UCA Global G2 Root
C=RO, O=CERTSIGN SA, OU=certSIGN ROOT CA G2
C=US, O=Certainly, CN=Certainly Root R1
C=CN, O=iTrusChina Co.,Ltd., CN=vTrus Root CA
C=US, O=Google Trust Services LLC, CN=GTS Root R1
C=US, O=Google Trust Services LLC, CN=GTS Root R2
C=NO, O=Buypass AS-983163327, CN=Buypass Class 2 Root CA
C=NO, O=Buypass AS-983163327, CN=Buypass Class 3 Root CA
C=CN, O=UniTrust, CN=UCA Extended Validation Root
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Root R46
C=US, O=IdenTrust, CN=IdenTrust Commercial Root CA 1
C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 3 G3
C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 1 G3
CN=Atos TrustedRoot Root CA RSA TLS 2021, O=Atos, C=DE
C=US, O=DigiCert, Inc., CN=DigiCert TLS RSA4096 Root G5
C=US, O=IdenTrust, CN=IdenTrust Public Sector Root CA 1
C=SK, L=Bratislava, O=Disig a.s., CN=CA Disig Root R2
C=TW, O=Chunghwa Telecom Co., Ltd., CN=HiPKI Root CA - G1
C=US, O=Internet Security Research Group, CN=ISRG Root X1
C=US, O=CommScope, CN=CommScope Public Trust RSA Root-01
C=US, O=CommScope, CN=CommScope Public Trust RSA Root-02
C=JP, O=Cybertrust Japan Co., Ltd., CN=SecureSign Root CA14
C=FI, O=Telia Finland Oyj, CN=Telia Root CA v2
C=CN, O=BEIJING CERTIFICATE AUTHORITY, CN=BJCA Global Root CA1
C=CN, O=TrustAsia Technologies, Inc., CN=TrustAsia TLS RSA Root CA
C=AT, O=e-commerce monitoring GmbH, CN=GLOBALTRUST 2020
OU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign
C=ES, O=FNMT-RCM, OU=AC RAIZ FNMT-RCM
C=CH, O=OISTE Foundation, CN=OISTE Server Root RSA G1
C=CN, O=GUANG DONG CERTIFICATE AUTHORITY CO.,LTD., CN=GDCA TrustAUTH R5 ROOT
C=US, O=SSL Corporation, CN=SSL.com TLS RSA Root CA 2022
C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication Root R46
C=CN, O=China Financial Certification Authority, CN=CFCA EV ROOT
C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA CYBER Root CA
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Trusted Root G4
C=CH, O=SwissSign AG, CN=SwissSign RSA TLS Root CA 2022 - 1
C=KR, O=NAVER BUSINESS PLATFORM Corp., CN=NAVER Global Root Certification Authority
C=GR, O=Hellenic Academic and Research Institutions CA, CN=HARICA TLS RSA Root CA 2021
C=CN, O=TrustAsia Technologies, Inc., CN=TrustAsia Global Root CA G3
C=US, O=Microsoft Corporation, CN=Microsoft RSA Root Certificate Authority 2017
C=DE, O=D-Trust GmbH, CN=D-TRUST EV Root CA 2 2023
C=DE, O=D-Trust GmbH, CN=D-TRUST BR Root CA 2 2023
C=TW, O=Chunghwa Telecom Co., Ltd., OU=ePKI Root Certification Authority
C=DE, O=Deutsche Telekom Security GmbH, CN=Telekom Security TLS RSA Root 2023
C=TN, O=Agence Nationale de Certification Electronique, CN=TunTrust Root CA
C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
C=PL, O=Asseco Data Systems S.A., OU=Certum Certification Authority, CN=Certum Trusted Root CA
C=HK, ST=Hong Kong, L=Hong Kong, O=Hongkong Post, CN=Hongkong Post Root CA 3
C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA 2
C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
C=US, ST=Illinois, L=Chicago, O=Trustwave Holdings, Inc., CN=Trustwave Global Certification Authority
C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com Root Certification Authority RSA
C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com EV Root Certification Authority RSA R2
serialNumber=G63287510, C=ES, O=ANF Autoridad de Certificacion, OU=ANF CA Raiz, CN=ANF Secure Server Root CA
C=ES, O=IZENPE S.A., CN=Izenpe.com
C=GR, L=Athens, O=Hellenic Academic and Research Institutions Cert. Authority, CN=Hellenic Academic and Research Institutions RootCA 2015
C=ES, CN=Autoridad de Certificacion Firmaprofesional CIF A62634068
C=FR, O=Dhimyotis, OU=0002 48146308100036, CN=Certigna Root CA
C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 3
CN=ACCVRAIZ1, OU=PKIACCV, O=ACCV, C=ES

@tyilo

tyilo commented Jul 28, 2026

Copy link
Copy Markdown
Author

Note: I have a binary that is run directly on Android without an app, so no JVM is available and thus I can't use rustls-platform-verifier.

@djc djc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems reasonable to me -- let's see what other maintainers think.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants