RE: VerifyPeer in OpenSSL vs DarwinSSL

From: Vincas Razma <>
Date: Thu, 17 Mar 2016 10:33:37 +0000

>> Only way to do that would be to use OpenSSL and generate cert bundle
>> using by getting certificates from Android APIs separately

> Is that possible? Have you done it? If so, can you share the resulting bundle?

I have only investigated that and seems there are APIs for getting root certs from OS, but did not have time to have full implementation. Main idea is to avoid delivering cert bundle that could outdate or be compromised (app developer thus being responsible for it being always valid)

