Charles Proxy在Android 7.0以上版本失效?Google Pixel(Oreo)握手异常求助
Hey there, I’ve dealt with this exact headache on Pixel devices running Oreo before—those post-Nougat network security changes really throw a wrench in SSL proxying. Let’s walk through the fixes that worked for me:
1. Install Charles’ Certificate to the System Certificate Store (Critical for Oreo+)
Android 7.0 (Nougat) and later block apps from trusting user-installed CA certificates by default. To get Charles working, you need to move its certificate into the system’s trusted store (requires root access):
- First, export the Charles root certificate: Go to
Help > SSL Proxying > Save Charles Root Certificateand save it as a.pemfile. - Calculate the certificate’s hash using this command (run it on your computer, not the device):
openssl x509 -subject_hash_old -in charles.pem | head -1 - Rename your
.pemfile tocacert-<HASH_VALUE>.0(replace<HASH_VALUE>with the output from the command above). - Push the renamed certificate to your Pixel’s system directory (you’ll need to remount
/systemas writable first):adb root adb remount /system adb push cacert-xxxxxx.0 /system/etc/security/cacerts/ adb shell chmod 644 /system/etc/security/cacerts/cacert-xxxxxx.0 - Reboot your device—this ensures the system picks up the new trusted certificate.
2. Configure App-Specific Network Security (No Root Needed for Your Own Apps)
If you’re testing an app you control and don’t want to root your Pixel, tweak its network security settings to trust user-installed certificates:
- Create a
network_security_config.xmlfile in your app’sres/xmldirectory with this content:<?xml version="1.0" encoding="utf-8"?> <network-security-config> <base-config cleartextTrafficPermitted="true"> <trust-anchors> <certificates src="system" /> <!-- Keep trusting system certs --> <certificates src="user" /> <!-- Allow trusting user-installed certs like Charles --> </trust-anchors> </base-config> </network-security-config> - Update your
AndroidManifest.xmlto reference this config in the<application>tag:<application ... android:networkSecurityConfig="@xml/network_security_config" ...> - Note: If your app has
android:debuggable="true"set, Android automatically allows trusting user certs for debug builds—this config is mainly for release builds or non-debuggable apps.
3. Double-Check Charles’ SSL Proxy Settings
Don’t overlook the basics:
- Make sure SSL Proxying is enabled in Charles: Go to
Proxy > SSL Proxying Settingsand add the specific domains you want to intercept (using*for all domains works, but isn’t ideal for security). - Verify your Pixel’s Wi-Fi proxy is set to your computer’s local IP address and the port Charles is listening on (default is 8888).
4. Clear Stored Certificate Caches
Sometimes old cached certificates cause handshake issues:
- Clear the cache for the app you’re testing (Settings > Apps > [Your App] > Storage > Clear Cache).
- Restart Charles and your Pixel to ensure no stale connections are lingering.
If you’re trying to proxy system apps (like Google Play Services), the system certificate install (step 1) is mandatory—system apps don’t respect the app-specific network security configs.
内容的提问来源于stack exchange,提问作者user9614814

