Certificate Error on Android using OneConnect

Last modified on 6 Oct, 2026. Revision 5
BehaviorWhen OneConnect connects to the gateway, the client validates the certificate the server presents. If validation fails, a Certificate Error is shown and the connection is aborted.The error means the client does not trust the certificate, not necessarily that the certificate is invalid. A certificate can be valid and unexpired yet still fail verification on a particular client.
Up to date for
15.00.08

Common issue

Android is stricter when validating certificate chains. iOS often fetches missing intermediate certificates itself (via AIA) to build the full chain, while Android does not.

If the server does not send the complete chain, the connection may still work on iOS but fail on Android.

Resolution

Add the full chain to the firewall, as shown below:

  1. Set the end-entity certificate as the OneConnect Host Certificate.
  2. Add the intermediate and root certificates under OneConnect Root Certificates.
  3. Deploy the configuration.


Verification

Run the following and confirm that all certificates in the chain are listed:

openssl s_client -connect <host>:443 -showcerts

Then retest the connection from an Android device.

External tool

Use https://whatsmychaincert.com/ to generate the full chain for the firewall or to test the presented certificate.


Related articles

No related articles found.