Skip to content

Android app doesn't prompt for client certificate with mutual TLS #2068

Description

@MEntOMANdo
  • I checked that my issue isn't already filed: Search open issues.
  • [n/a] I checked the relevant camera/device and/or plugin Log in the Management Console for errors or warnings that may help identify and resolve the issue myself.

Describe the bug
Scrypted is working fine. I have a reverse proxy in front of it for external access (Cloudflare tunnel or integration isn't sufficient for my needs). If I use regular OIDC authentication to authenticate the user, and then pass them through to Scrypted, it works fine.

If I enforce mTLS and access the public url from a web browser, the browser prompts to select a certificate, and then it proceeds as usual. Great.

However, the Android app doesn't prompt for a certificate, nor does it redirect to a web browser to support either mTLS or any third-party https authentication. It only works with the built-in authentication.

To Reproduce
Steps to reproduce the behavior:

  1. Install Scrypted
  2. In the Cloud plugin, enable custom domain
  3. Configure a reverse proxy properly, using OIDC authentication (or none), forwarding to the port noted in the Cloud plugin
  4. Verify that everything works as it should, from a desktop web browser, mobile browser and the Android app
  5. Alter the reverse proxy to validate the client via mTLS, and properly deploy certificates to the client devices
  6. Observe that Scrypted can be accessed from a desktop web browser, a mobile browser (in both cases, prompting for certificates as needed), but not the Android app, where it just says "TypeError: Failed to fetch"

Server (please complete the following information):

  • OS: macOS 26
  • Installation Method: Desktop App

Hardware Model (please complete the following information):
N/A

Client (please complete the following information, if applicable):

  • Desktop browsers (chrome, firefox)
  • mobile browser (firefox)
  • Scrypted Android app

Additional context
Would be nice to either provide a way to upload the certificate into the mobile app, or have the app use the normal OS flows for TLS that display the Android system-level certificate popup.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions