make-apk-accept-ca-certificate.md (3491B)
1 --- 2 title: "Make an APK Trust a User CA Certificate" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/make-apk-accept-ca-certificate.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/make-apk-accept-ca-certificate.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Make an APK Trust a User CA Certificate 14 15 Android applications can restrict which certificate authorities they trust. In an authorized test environment, repackaging an APK with a Network Security Configuration that trusts user-installed CAs can make HTTPS traffic inspection possible. This does not automatically bypass certificate pinning implemented elsewhere in the application.<sup>[[1]](#references)</sup> 16 17 ## Automatic 18 19 [`apk-mitm`](https://github.com/shroudedcode/apk-mitm) automates APK patching for HTTPS inspection and includes patches for several common certificate-pinning implementations.<sup>[[2]](#references)</sup> 20 21 ## Manual 22 23 Decompile the APK: 24 25 ```bash 26 apktool d app.apk 27 ``` 28 29  30 31 In `AndroidManifest.xml`, add the following attribute to the `<application>` element if it is not already set:<sup>[[1]](#references)</sup> 32 33 `android:networkSecurityConfig="@xml/network_security_config"` 34 35 Before adding: 36 37  38 39 After adding: 40 41  42 43 Create or update `res/xml/network_security_config.xml` with the following content. The `system` source keeps the preinstalled trust anchors, while `user` adds user-installed CAs:<sup>[[1]](#references)</sup> 44 45 ```html 46 <network-security-config> 47 <base-config> 48 <trust-anchors> 49 <!-- Trust preinstalled CAs --> 50 <certificates src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/system" /> 51 <!-- Additionally trust user-added CAs --> 52 <certificates src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/user" /> 53 </trust-anchors> 54 </base-config> 55 </network-security-config> 56 ``` 57 58 Rebuild the APK: 59 60 ```bash 61 apktool b app -o patched.apk 62 ``` 63 64  65 66 Repackaging invalidates the original signature, so sign the rebuilt APK before installing it. [See the APK signing section](/hacktricks/mobile-pentesting/android-app-pentesting/smali-changes#sign-the-new-apk). 67 68 ## References 69 70 - [1] [Android Developers - Network Security Configuration](https://developer.android.com/privacy-and-security/security-config) 71 - [2] [apk-mitm - Prepare Android APK files for HTTPS inspection](https://github.com/shroudedcode/apk-mitm)