I've managed to cross-compile OpenSSL for ARMv6 for use with the Android NDK and get it to run within my application. However, when attempting to establish an HTTPS connection to a well-known host (such as https://google.com), I always receive the error "The SSL certificate is invalid."

However, I have no difficulty displaying secure pages within any of my device's browsers (the stock browser, Chrome, Firefox, etc.). Therefore I can only assume OpenSSL isn't finding the root certificates stored on the device.

My question then breaks down into two very related sub-questions:

  • Where does Android store the root certificates on the device?
  • How can I point OpenSSL to them?
Edit
Report