I'm trying to install certificates without prompting the user. I know this is not good practice, but that's what PM wants.
Using KeyChain.createInstallIntent()
, I can get Android to launch the certificate installation dialog by calling startActivity
. However, when I pass the intent to sendBroadcast
, nothing happens. Maybe the platform doesn't support this for security reasons?
String CERT_FILE = Environment.getExternalStorageDirectory() + "/test/IAT.crt";
Intent intent = KeyChain.createInstallIntent();
try {
FileInputStream certIs = new FileInputStream(CERT_FILE);
byte [] cert = new byte[(int)certFile.length()];
certIs.read(cert);
X509Certificate x509 = X509Certificate.getInstance(cert);
intent.putExtra(KeyChain.EXTRA_CERTIFICATE, x509.getEncoded());
intent.putExtra(KeyChain.EXTRA_NAME, "IAT Cert");
EapActivity.this.startActivityForResult(intent, 0); // this works but shows UI
EapActivity.this.sendBroadcast(intent); // this doesn't install cert
} catch (IOException e) {
Only a system user application can silently install a CA certificate. On Lollipop though, Google introduced silent certificate management API through DevicePolicyManager, but you would either have to be Android-for-Work profile owner or device owner.
Few if any
Intent
objects that you would pass tostartActivity()
would work withsendBroadcast()
. They are independent channels of the quasi-message bus that is theIntent
system.Based on the @ospider's answer, i managed to succesfully install the cert like this way:
I got the name of the copied file (
807e3b02.0
) by installing manually the cert i wanted to automate and seeing how Android saved it (whithadb shell ls -l /data/misc/user/0/cacerts-added/
)Hope this help.
Regards.
If you have root privilege, you could copy the certs file to
/data/misc/user/0/cacerts-added/
You can only install certificates silently if you have system privileges. Showing up a confirmation dialog is intentional, since trusting certificates can have serious consequences -- Android could happily open phishing sites without a warning, etc. That said, the dialog in ICS/JB is pretty bad -- it doesn't tell you what certificate you are installing and who issued it, just that it's a CA certificate, which is kind of obvious.
So, either use the public
KeyChain
API and usestartActivity()
to get the confirmation dialog, or pre-provision devices before handling them to users.Update: In Android 4.4,
DevicePolicyManager
has a hidden API (installCaCert
) that allows you to install certificates silently. You need theMANAGE_CA_CERTIFICATES
permission, which issignature|system
, so still not doable for user-installed apps.For non-system app developers - the simple answer is it can not be done without user interaction.
For System App developers, I found the following solution, NB you must run the app with the system user id and sign the app with the system key or the service will reject your attempts to install the certificate.
Step 1 - Create interface
Create a new package in your project: android.security, then copy IKeyChainService.aidl into this package.
Step 2 - Bind to service and install certificate
The Activity gives an example of how to install a CA certificate:
I hope this helps someone - it took me a long time to work it out :)