Android API 23以下版本应用无法连接服务器问题排查求助
Hey there, let’s unpack this issue clearly—since your app ran stable for years and only users on Android API 23 (Android 6.0) and below are facing server connection failures starting May 30, 2020, this is almost certainly not an ISP problem. Here’s why, plus the most likely culprits and fixes:
First: Why It’s Not an ISP Issue
ISP-related problems (outages, routing blocks, etc.) affect broad groups of users—either everyone in a region, or all users regardless of device/OS version. They don’t target a specific Android API level. So we can rule that out right away.
Most Likely Causes (Google/Platform-Related)
The timeline lines up with major security changes Google pushed around 2020 that directly impact older Android versions:
TLS Protocol Version Enforcement
Google began pushing developers and server admins to phase out outdated TLS versions (TLS 1.0 and 1.1) in 2019-2020, with many services disabling them by mid-2020. The catch: Android API <23 devices do not support TLS 1.2+ by default. If your server upgraded its TLS configuration around May 2020 to disable older protocols, these devices can’t complete the TLS handshake and will fail to connect. This is the #1 cause for this exact scenario.Network Security Policy (NSP) Compatibility
Android 6.0 (API 23) introduced the Network Security Policy, which enforces HTTPS by default and restricts untrusted certificates. If your server updated its SSL certificate around that time (e.g., switched to a new certificate authority), older API devices might not have the corresponding root certificate pre-installed. Additionally, if your app’s NSP configuration doesn’t include exceptions for older devices, it can block connections that worked previously.Google Play Services Deprecations
While less common, if your app relies on Google Play Services components for network requests (like Firebase Cloud Messaging or Google Sign-In), Google may have ended support for API <23 in updates rolled out around May 2020. This would break network-dependent features on older devices without affecting newer ones.
How to Diagnose & Fix
Capture Network Traffic
Use a tool like Charles Proxy or Wireshark to capture connection attempts from an API <23 device. Look for TLS handshake errors (e.g., "Protocol version not supported" or alert code 40)—this confirms a TLS version mismatch.Test Server TLS Configuration
Run this command in your terminal to check if your server still supports older TLS versions:openssl s_client -connect your-server-domain:443 -tls1If the connection fails, your server has disabled TLS 1.0/1.1. To fix this, you’ll need to add TLS 1.2 support to your app for API <23 devices (e.g., configuring OkHttp to enable TLS 1.2 programmatically).
Check Certificate Compatibility
Verify that your server’s SSL certificate is trusted by older Android devices. Some modern CAs use root certificates that aren’t pre-installed on API <23 devices—you may need to include the root certificate in your app’s assets and reference it in your network security config.
内容的提问来源于stack exchange,提问作者Jahury

