You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android Studio本地环境HTTPS通信报错:Trust anchor for certification path not found in localhost

Fixing "Trust anchor for certification path not found in localhost" with Let's Encrypt on Android

Hey there, let's work through this trust anchor error you're facing with your Android app and Let's Encrypt certificate for localhost. I've dealt with similar issues during university project development, so here's a breakdown of what's going wrong and how to fix it:

First, the core issue: Let's Encrypt doesn't issue certificates for localhost

Let's Encrypt requires publicly verifiable domain names to issue valid SSL certificates, and localhost is a local-only address that can't be verified publicly. That means the certificate you're using either:

  • Isn't actually issued for localhost (it's for a public domain you own), but you're accessing your local server via localhost, causing a domain mismatch
  • Or you tried to generate a Let's Encrypt certificate for localhost (which isn't possible), leading to an invalid or untrusted cert

Solutions to resolve the error

1. Use Android's Network Security Config to trust your certificate

If you're testing with a Let's Encrypt certificate for a public domain (and you've mapped that domain to your local server via the hosts file), you can tell Android to trust that specific certificate:

  • Export your Let's Encrypt certificate as a PEM file, then place it in your app's app/src/main/res/raw/ directory (name it something like my_ssl_cert.pem)
  • Create a network_security_config.xml file in app/src/main/res/xml/ with this content:
    <?xml version="1.0" encoding="utf-8"?>
    <network-security-config>
        <domain-config cleartextTrafficPermitted="false">
            <!-- Replace with your public domain (e.g., myproject.example.com) -->
            <domain includeSubdomains="true">your-public-domain.com</domain>
            <trust-anchors>
                <!-- Trust your custom Let's Encrypt cert -->
                <certificates src="@raw/my_ssl_cert" />
                <!-- Keep trusting system default certificates -->
                <certificates src="system" />
            </trust-anchors>
        </domain-config>
    </network-security-config>
    
  • Update your AndroidManifest.xml to reference this config in the <application> tag:
    <application
        ...
        android:networkSecurityConfig="@xml/network_security_config">
    

2. Switch to a locally trusted certificate (for pure localhost testing)

Since Let's Encrypt can't cover localhost, use a tool like mkcert to generate a local, trusted SSL certificate:

  • Install mkcert on your development machine
  • Run mkcert localhost to generate a certificate and key pair for localhost
  • Configure your local server to use these files
  • Export the root CA generated by mkcert (run mkcert -CAROOT to find the location), then import it into your Android device:
    • On your phone, go to Settings > Security > Encryption & credentials > Install a certificate > CA certificate
    • Locate the exported CA file and follow the prompts to install it

3. Map your public domain to localhost (via hosts file)

If you have a valid Let's Encrypt certificate for a public domain, edit your device's hosts file (requires root, or use a VPN tool like AdGuard to override DNS) to point that domain to 127.0.0.1 or your local server's IP. This way, your app accesses the domain the certificate was issued for, avoiding the trust error.

Quick check to confirm

Make sure when you access your server via HTTPS, the certificate's subject alternative name (SAN) matches the address you're using (either your public domain or localhost). You can verify this by opening the URL in a desktop browser and checking the certificate details.

内容的提问来源于stack exchange,提问作者FirexXY

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 18:32:42