You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Charles Proxy在Android 7.0以上版本失效?Google Pixel(Oreo)握手异常求助

Fixing Charles Proxy Handshake Failures on Android Oreo (Google Pixel)

Hey there, I’ve dealt with this exact headache on Pixel devices running Oreo before—those post-Nougat network security changes really throw a wrench in SSL proxying. Let’s walk through the fixes that worked for me:

1. Install Charles’ Certificate to the System Certificate Store (Critical for Oreo+)

Android 7.0 (Nougat) and later block apps from trusting user-installed CA certificates by default. To get Charles working, you need to move its certificate into the system’s trusted store (requires root access):

  • First, export the Charles root certificate: Go to Help > SSL Proxying > Save Charles Root Certificate and save it as a .pem file.
  • Calculate the certificate’s hash using this command (run it on your computer, not the device):
    openssl x509 -subject_hash_old -in charles.pem | head -1
    
  • Rename your .pem file to cacert-<HASH_VALUE>.0 (replace <HASH_VALUE> with the output from the command above).
  • Push the renamed certificate to your Pixel’s system directory (you’ll need to remount /system as writable first):
    adb root
    adb remount /system
    adb push cacert-xxxxxx.0 /system/etc/security/cacerts/
    adb shell chmod 644 /system/etc/security/cacerts/cacert-xxxxxx.0
    
  • Reboot your device—this ensures the system picks up the new trusted certificate.

2. Configure App-Specific Network Security (No Root Needed for Your Own Apps)

If you’re testing an app you control and don’t want to root your Pixel, tweak its network security settings to trust user-installed certificates:

  • Create a network_security_config.xml file in your app’s res/xml directory with this content:
    <?xml version="1.0" encoding="utf-8"?>
    <network-security-config>
        <base-config cleartextTrafficPermitted="true">
            <trust-anchors>
                <certificates src="system" /> <!-- Keep trusting system certs -->
                <certificates src="user" /> <!-- Allow trusting user-installed certs like Charles -->
            </trust-anchors>
        </base-config>
    </network-security-config>
    
  • Update your AndroidManifest.xml to reference this config in the <application> tag:
    <application
        ...
        android:networkSecurityConfig="@xml/network_security_config"
        ...>
    
  • Note: If your app has android:debuggable="true" set, Android automatically allows trusting user certs for debug builds—this config is mainly for release builds or non-debuggable apps.

3. Double-Check Charles’ SSL Proxy Settings

Don’t overlook the basics:

  • Make sure SSL Proxying is enabled in Charles: Go to Proxy > SSL Proxying Settings and add the specific domains you want to intercept (using * for all domains works, but isn’t ideal for security).
  • Verify your Pixel’s Wi-Fi proxy is set to your computer’s local IP address and the port Charles is listening on (default is 8888).

4. Clear Stored Certificate Caches

Sometimes old cached certificates cause handshake issues:

  • Clear the cache for the app you’re testing (Settings > Apps > [Your App] > Storage > Clear Cache).
  • Restart Charles and your Pixel to ensure no stale connections are lingering.

If you’re trying to proxy system apps (like Google Play Services), the system certificate install (step 1) is mandatory—system apps don’t respect the app-specific network security configs.

内容的提问来源于stack exchange,提问作者user9614814

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:40:17