无法捕获Android模拟器中应用的网络流量——SSL握手失败求助
I've run into this exact headache before when trying to proxy SSL traffic from Android emulators with Charles. Let's walk through the most reliable fixes that should get you up and running smoothly:
1. Install Charles Certificate as a System Certificate (Critical for Android 7+)
Starting with Android 7, apps by default only trust system-installed certificates—not the user-installed ones you set up earlier. That's almost certainly why the handshake is failing. Here's how to move your certificate to the system store:
- First, export your Charles root certificate as a PEM file: Go to
Help > SSL Proxying > Save Charles Root Certificate...and select PEM format. - Rename the exported file to something like
00000000.0(the suffix must be.0; the 8-digit prefix can be any number). - Run these adb commands to push the certificate to the emulator's system certificate directory:
adb root adb remount adb push /path/to/your/renamed-cert.0 /system/etc/security/cacerts/ adb shell chmod 644 /system/etc/security/cacerts/00000000.0 adb reboot
After the emulator restarts, it will recognize the Charles certificate as a trusted system root.
2. Add Network Security Config for Target Apps (Alternative to System Cert)
If you're testing your own app and don't want to mess with system certificates, you can configure the app to explicitly trust user-installed certificates:
- Create a
res/xml/network_security_config.xmlfile in your app project with this content:<?xml version="1.0" encoding="utf-8"?> <network-security-config> <base-config cleartextTrafficPermitted="true"> <trust-anchors> <certificates src="system" /> <certificates src="user" /> <!-- Allows trusting user-installed certs --> </trust-anchors> </base-config> </network-security-config> - Update your
AndroidManifest.xmlto reference this config in the<application>tag:<application ... android:networkSecurityConfig="@xml/network_security_config">
Rebuild and reinstall the app, then try proxying again.
3. Verify SSL Proxy Locations in Charles
Double-check that you've added the correct targets to your SSL Proxy Settings:
- Go to
Proxy > SSL Proxy Settings - Make sure
Enable SSL Proxyingis checked, and your target domain (or*:443for all HTTPS traffic) is listed inSSL Proxy Locationsand marked as checked. Missing this can cause handshake failures even if your certificate is properly installed.
4. Double-Check Emulator Proxy Settings
Ensure your emulator's WiFi proxy is pointing to your machine's actual LAN IP (not localhost or 127.0.0.1—the emulator can't reach your local machine via those addresses). Use your machine's local network IP (e.g., 192.168.1.100) and the port Charles is using (default is 8888).
5. Confirm Charles Certificate Validity
Quickly check if your Charles root certificate is expired: Go to Help > SSL Proxying > Install Charles Root Certificate on a Mobile Device or Remote Browser... and verify the certificate's expiration date. If it's expired, regenerate and reinstall it.
These steps should resolve the certificate_unknown handshake failure in most cases.
内容的提问来源于stack exchange,提问作者user0007

