fix(errors): say when the server's certificate is the problem - #80
Merged
Merged
Conversation
A TLS failure is an IOException, so it was reported as "Network error, check your connection". Someone whose server uses a private CA, a certificate for a different name, or an expired one went off to debug their network when the answer was on the server. Release builds now name the three certificate cases: - **Not trusted**: says so, and that certificates installed on the device are not used, which is the obvious next question from anyone who installed their own CA and wonders why it made no difference. - **Issued for another address**: the classic case of entering a server by IP when its certificate names a hostname. - **Expired or not yet valid**: points at the device clock as well as the certificate, since a wrong clock produces the same error. The check reads the handshake exception's cause chain, and only uses a certificate message when a certificate is actually the cause. A handshake that fails for another reason, such as the server dropping the connection, keeps the network message, and a test holds that line. Debug builds accept any certificate, so none of this shows there.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A TLS failure is an
IOException, so it was reported as "Network error, check your connection". Someone whose server uses a private CA, a certificate for another name, or an expired one would go off to debug their network when the answer was on the server.Release builds now name the three certificate cases:
The check reads the handshake exception's cause chain and only uses a certificate message when a certificate really is the cause. A handshake that fails for another reason, such as the server dropping the connection, keeps the network message. None of this shows on debug builds, which accept any certificate.
This changes wording only. What the app trusts is exactly what it was.
Checked
assembleOpenDebugon this branch.