[GH-ISSUE #1435] Support ignoring of SSL exceptions on Android. #950

Closed
opened 2026-02-25 22:38:32 +03:00 by kerem · 3 comments
Owner

Originally created by @RobertZenz on GitHub (Nov 30, 2023).
Original GitHub issue: https://github.com/floccusaddon/floccus/issues/1435

Describe the feature you'd like to request

The ability to ignore SSL exceptions and errors in the Android app when connecting to a server.

Describe the solution you'd like

Currently when trying to connect to a machine in the local network, for example "https://192.168.0.128/" an error message is displayed that an SSL-Exception was thrown. That is to be expected, as "192.168.0.128" will never match the certificate. Being able to ignore that exception would be great.

Basically what is needed is the possibility to accept self-signed certificates on Android and ignore when there is a problem with the certificate (TLD of certificate not matching address).

Describe alternatives you've considered

The most suggested "solution" is to have your router "reroute" the TLD provided in the certificate of the machine to the local machine within the local network. In many setups this is neither feasible nor possible.

Originally created by @RobertZenz on GitHub (Nov 30, 2023). Original GitHub issue: https://github.com/floccusaddon/floccus/issues/1435 ### Describe the feature you'd like to request The ability to ignore SSL exceptions and errors in the Android app when connecting to a server. ### Describe the solution you'd like Currently when trying to connect to a machine in the local network, for example "https://192.168.0.128/" an error message is displayed that an SSL-Exception was thrown. That is to be expected, as "192.168.0.128" will never match the certificate. Being able to ignore that exception would be great. Basically what is needed is the possibility to accept self-signed certificates on Android and ignore when there is a problem with the certificate (TLD of certificate not matching address). ### Describe alternatives you've considered The most suggested "solution" is to have your router "reroute" the TLD provided in the certificate of the machine to the local machine within the local network. In many setups this is neither feasible nor possible.
kerem 2026-02-25 22:38:32 +03:00
Author
Owner

@github-actions[bot] commented on GitHub (Nov 30, 2023):

Hello 👋

Thank you for taking the time to open this issue with floccus. I know it's frustrating when software
causes problems. You have made the right choice to come here and open an issue to make sure your problem gets looked at
and if possible solved.
I'm Marcel and I created floccus and have been maintaining it ever since.
I currently work for Nextcloud which leaves me with less time for side projects like this one
than I used to have.
I still try to answer all issues and if possible fix all bugs here, but it sometimes takes a while until I get to it.
Until then, please be patient.
Note also that GitHub is a place where people meet to make software better together. Nobody here is under any obligation
to help you, solve your problems or deliver on any expectations or demands you may have, but if enough people come together we can
collaborate to make this software better. For everyone.
Thus, if you can, you could also have a look at other issues to see whether you can help other people with your knowledge
and experience. If you have coding experience it would also be awesome if you could step up to dive into the code and
try to fix the odd bug yourself. Everyone will be thankful for extra helping hands!
One last word: If you feel, at any point, like you need to vent, this is not the place for it; you can go to the forum,
to twitter or somewhere else. But this is a technical issue tracker, so please make sure to
focus on the tech and keep your opinions to yourself.

I look forward to working with you on this issue
Cheers 💙

<!-- gh-comment-id:1834097378 --> @github-actions[bot] commented on GitHub (Nov 30, 2023): Hello :wave: Thank you for taking the time to open this issue with floccus. I know it's frustrating when software causes problems. You have made the right choice to come here and open an issue to make sure your problem gets looked at and if possible solved. I'm Marcel and I created floccus and have been maintaining it ever since. I currently work for Nextcloud which leaves me with less time for side projects like this one than I used to have. I still try to answer all issues and if possible fix all bugs here, but it sometimes takes a while until I get to it. Until then, please be patient. Note also that GitHub is a place where people meet to make software better *together*. Nobody here is under any obligation to help you, solve your problems or deliver on any expectations or demands you may have, but if enough people come together we can collaborate to make this software better. For everyone. Thus, if you can, you could also have a look at other issues to see whether you can help other people with your knowledge and experience. If you have coding experience it would also be awesome if you could step up to dive into the code and try to fix the odd bug yourself. Everyone will be thankful for extra helping hands! One last word: If you feel, at any point, like you need to vent, this is not the place for it; you can go to the forum, to twitter or somewhere else. But this is a technical issue tracker, so please make sure to focus on the tech and keep your opinions to yourself. I look forward to working with you on this issue Cheers :blue_heart:
Author
Owner

@marcelklehr commented on GitHub (Dec 5, 2023):

Hello @RobertZenz

due to security concerns I will not add a setting to floccus that allows people to ignore TLS errors and warnings. Self-signed certificates have known drawbacks that anyone will need to mitigate themselves if they choose to go down that path. Getting android and android apps to accept them is one of these drawbacks. See #208 for discussions about this.
In my opinion there is a tested and true path even for selfhosting at home: Get a cheap domain and a free certificate from letsencrypt, or sign up for a subdomain on a service like duckdns.
Please understand that I need to close this request.
All the best for your future endeavors!

<!-- gh-comment-id:1841289152 --> @marcelklehr commented on GitHub (Dec 5, 2023): Hello @RobertZenz due to security concerns I will not add a setting to floccus that allows people to ignore TLS errors and warnings. Self-signed certificates have known drawbacks that anyone will need to mitigate themselves if they choose to go down that path. Getting android and android apps to accept them is one of these drawbacks. See #208 for discussions about this. In my opinion there is a tested and true path even for selfhosting at home: Get a cheap domain and a free certificate from letsencrypt, or sign up for a subdomain on a service like duckdns. Please understand that I need to close this request. All the best for your future endeavors!
Author
Owner

@github-actions[bot] commented on GitHub (Dec 6, 2024):

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

<!-- gh-comment-id:2521813080 --> @github-actions[bot] commented on GitHub (Dec 6, 2024): This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/floccus#950
No description provided.