[ale] Android certificates without screen lock?

Alex Carver agcarver+ale at acarver.net
Mon Nov 17 23:01:13 EST 2014


On 2014-11-17 19:57, Derek Atkins wrote:
> Hi,
> 
> On Mon, November 17, 2014 10:26 pm, Alex Carver wrote:
>> Anyone know how to install a user certificate on KitKat without
>> requiring a screen lock?  My Google-fu is failing and every time I try
>> to install the certificate I'm asked to activate a screen lock
>> PIN/password.
>>
>> I'm trying to upload a self-signed certificate for my mail server.
> 
> Are you actually trying to install a *USER* certificate and not a *SERVER*
> certificate?  Why would you have a self-signed user certificate?  How
> would the server verify that?!?
> 
> But no, on Android you cannot install a *user* certificate without a PIN,
> because it uses the PIN to turn on the system keystore.
> 
> For a server certificate you can just tell android to accept it when you
> connect and it will remember it.
> 

Good point, I was thinking in my head "user installed".  Yes, it's the
server's certificate but Android is not prompting me to accept the cert.
 I have to set the email client to accept all certificates.  If I don't,
it never prompts to store.



More information about the Ale mailing list