# Use self-signed certificates in Android

**URL:** <https://community.pexip.com/t/use-self-signed-certificates-in-android/64>\
**Category:** Android\
**Created:** [August 31, 2022, 6:54am UTC](https://community.pexip.com/t/use-self-signed-certificates-in-android/64 "2022-08-31T06:54:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcos.cereijo](https://dub1.discourse-cdn.com/flex005/user_avatar/community.pexip.com/marcos.cereijo/32/14_2.png) [@marcos.cereijo](https://community.pexip.com/u/marcos.cereijo)\
**Post date:** [August 31, 2022, 6:54am UTC](https://community.pexip.com/t/use-self-signed-certificates-in-android/64/1 "2022-08-31T06:54:16Z")

</div>

We should always use valid certificates for our Infinity deployments, however, this is not always possible. We could have a very specific deployment in our lab or be waiting for the client to deliver the certificates.

In all these cases, we can use the following function to override the default TrustManager.

| ⚠ WARNING: This code is only for testing. Get rid of it as soon as possible and never include it in a production package. |
| --- |

So, instead of using:

```nohighlight
val okHttpClient = OkHttpClient()

```

It’s possible to use this:

```nohighlight
val okHttpClientUnsecure = getUnsecureOkHttpClient()

```

Here is the function that creates the `OkHttpClient` that not validate the certificate:

```nohighlight
private fun getUnsecureOkHttpClient(): OkHttpClient {
    try {
        // Create a trust manager that does not validate certificate chains
        val trustAllCerts = arrayOf<TrustManager>(object : X509TrustManager {
            @Throws(CertificateException::class)
            override fun checkClientTrusted(
                chain: Array<java.security.cert.X509Certificate>,
                authType: String
            ) {
            }

            @Throws(CertificateException::class)
            override fun checkServerTrusted(
                chain: Array<java.security.cert.X509Certificate>,
                authType: String
            ) {
            }

            override fun getAcceptedIssuers(): Array<java.security.cert.X509Certificate> {
                return arrayOf()
            }
        })
        // Install the all-trusting trust manager
        val sslContext = SSLContext.getInstance("SSL")
        sslContext.init(null, trustAllCerts, java.security.SecureRandom())
        // Create an ssl socket factory with our all-trusting manager
        val sslSocketFactory = sslContext.socketFactory
        val builder = OkHttpClient.Builder()
        builder.sslSocketFactory(sslSocketFactory, trustAllCerts[0] as X509TrustManager)
        builder.hostnameVerifier(hostnameVerifier = HostnameVerifier { _, _ -> true })
        return builder.build()
    } catch (e: Exception) {
        throw RuntimeException(e)
    }
}

```

---

<div class="post-metadata">

**Author:** ![marcos.cereijo](https://dub1.discourse-cdn.com/flex005/user_avatar/community.pexip.com/marcos.cereijo/32/14_2.png) [@marcos.cereijo](https://community.pexip.com/u/marcos.cereijo)\
**Post date:** [August 31, 2022, 6:54am UTC](https://community.pexip.com/t/use-self-signed-certificates-in-android/64/2 "2022-08-31T06:54:46Z")

</div>


