[PR #6941] [client] Support user added CAs in android client #29282

Open
opened 2026-08-05 08:07:48 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6941
Author: @prixeus
Created: 7/28/2026
Status: 🔄 Open

Base: mainHead: fix-android-ca


📝 Commits (1)

  • e609786 [client] Support user added CAs in android client

📊 Changes

10 files changed (+104 additions, -70 deletions)

View changed files

client/android/certpool.go (+20 -0)
📝 client/grpc/dialer.go (+2 -10)
📝 client/internal/auth/device_flow.go (+2 -11)
📝 client/internal/auth/pkce_flow.go (+18 -2)
📝 flow/client/client.go (+2 -7)
📝 proxy/server.go (+2 -8)
📝 shared/relay/client/dialer/ws/ws.go (+2 -10)
📝 shared/relay/tls/client_dev.go (+2 -11)
📝 shared/relay/tls/client_prod.go (+2 -11)
util/certpool.go (+52 -0)

📄 Description

The android stores the Certificate Authorities separately which are installed by the user. The Golang ecosystem does not care about them by default, so there was no possibility to use them in self-hosted environment on android clients with user supplied CA.
As my understanding to fix that the android code should collect the Certificates Authorities with java API, supply them to go code, and consume it combined with the system provided CAs.
By default the system CAs will be used in Golang.

Describe your changes

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Added some in-line comments in go code

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • New Features
    • Added support for importing Android CA certificates to extend trusted TLS roots.
  • Improvements
    • Centralized TLS certificate trust around a shared CA pool for gRPC, OAuth/PKCE flows, relay/WebSocket connections, and management links.
    • When system trust is unavailable, the client still initializes from bundled roots, and the shared pool is used consistently across connections.
    • This reduces certificate-verification inconsistencies across different parts of the client.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6941 **Author:** [@prixeus](https://github.com/prixeus) **Created:** 7/28/2026 **Status:** 🔄 Open **Base:** `main` ← **Head:** `fix-android-ca` --- ### 📝 Commits (1) - [`e609786`](https://github.com/netbirdio/netbird/commit/e609786e7efaa368466d67218da10bfd8bb4010e) [client] Support user added CAs in android client ### 📊 Changes **10 files changed** (+104 additions, -70 deletions) <details> <summary>View changed files</summary> ➕ `client/android/certpool.go` (+20 -0) 📝 `client/grpc/dialer.go` (+2 -10) 📝 `client/internal/auth/device_flow.go` (+2 -11) 📝 `client/internal/auth/pkce_flow.go` (+18 -2) 📝 `flow/client/client.go` (+2 -7) 📝 `proxy/server.go` (+2 -8) 📝 `shared/relay/client/dialer/ws/ws.go` (+2 -10) 📝 `shared/relay/tls/client_dev.go` (+2 -11) 📝 `shared/relay/tls/client_prod.go` (+2 -11) ➕ `util/certpool.go` (+52 -0) </details> ### 📄 Description The android stores the Certificate Authorities separately which are installed by the user. The Golang ecosystem does not care about them by default, so there was no possibility to use them in self-hosted environment on android clients with user supplied CA. As my understanding to fix that the android code should collect the Certificates Authorities with java API, supply them to go code, and consume it combined with the system provided CAs. By default the system CAs will be used in Golang. ## Describe your changes ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [X] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [X] Documentation is **not needed** for this change (explain why) Added some in-line comments in go code ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6941"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787840014&installation_model_id=427504&pr_number=6941&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6941&signature=0bfc62d3d319e9035608d5757b7a31cd7ce99bf7433fe347b91e11029d4d2233"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>@codesmith-bot</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for importing Android CA certificates to extend trusted TLS roots. * **Improvements** * Centralized TLS certificate trust around a shared CA pool for gRPC, OAuth/PKCE flows, relay/WebSocket connections, and management links. * When system trust is unavailable, the client still initializes from bundled roots, and the shared pool is used consistently across connections. * This reduces certificate-verification inconsistencies across different parts of the client. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:07:48 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29282