# Android App problem

**URL:** https://farmos.discourse.group/t/android-app-problem/688
**Category:** Field Kit
**Created:** [March 2, 2021, 8:33pm UTC](https://farmos.discourse.group/t/android-app-problem/688 "2021-03-02T20:33:07Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![darrenjlobb](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@darrenjlobb](https://farmos.discourse.group/u/darrenjlobb)
#### Post date: [March 2, 2021, 8:33pm UTC](https://farmos.discourse.group/t/android-app-problem/688/1 "2021-03-02T20:33:07Z")

</div>

Hi Guys,

Have been using FarmOS for number of years now, always from a browser, found the download for the android APK, installed fine, but for some reason I cant seem to connect to my server? I enter the details and it just sits with spinning circle…

I am able to connect with http and https in the browser (after accepting security warning for https in chrome)…so think ssl is working as see the app forces it?

Its hosted locally on the network…

Any thoughts?

---

<div class="post-metadata">

### Author: ![jgaehring](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/jgaehring/32/927_2.png) [@jgaehring](https://farmos.discourse.group/u/jgaehring)
#### Post date: [March 2, 2021, 8:55pm UTC](https://farmos.discourse.group/t/android-app-problem/688/2 "2021-03-02T20:55:01Z")

</div>

Hi there, @darrenjlobb. Welcome to the forum!

You’re correct in assuming SSL is required. I’m a little concerned though if you’re getting warnings about https in the browser. Chrome doesn’t usually do that unless there’s something it doesn’t like about the certificate. Is it a self-signed certificate by any chance?

Also, I would probably recommend running the mobile as from the PWA website, instead of the Play Store APK. We’re not updating it as frequently b/c of general issues with native releases, but it’s the same app, and can even be “installed” to your home screen. More details here:

> [@Field Kit: a platform dilemma](https://farmos.discourse.group/t/field-kit-a-platform-dilemma/433):
>
> Hi everyone! As you might know, we’ve been in the beta phase for farmOS Field Kit for quite some time, while we try to nail down the core functionality and reach a level of relative stability. As we do so, we encourage users to test it out and provide feedback, and because we’re using a “Hybrid App” approach, we’re able to do so across 3 separate platforms: native Android (via the Play Store), native iOS (via Apple’s TestFlight), and on the web as a Progressive Web App (PWA) at [https://farmos.a…](https://farmos.app)

Let me know if you’re still having trouble, hope this helps!

---

<div class="post-metadata">

### Author: ![darrenjlobb](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@darrenjlobb](https://farmos.discourse.group/u/darrenjlobb)
#### Post date: [March 2, 2021, 9:03pm UTC](https://farmos.discourse.group/t/android-app-problem/688/3 "2021-03-02T21:03:21Z")

</div>

I did use the PWA, sorry should have said in the first post…

With regard to the certificate, its hosted here locally on the network, so as far as i’m aware, chrome will always behave like this? It works fine once you accept it and proceed…just like alot of network appliances hosted locally that use https?

Is this why the app isnt working do we think? What are others doing?

---

<div class="post-metadata">

### Author: ![jgaehring](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/jgaehring/32/927_2.png) [@jgaehring](https://farmos.discourse.group/u/jgaehring)
#### Post date: [March 2, 2021, 9:21pm UTC](https://farmos.discourse.group/t/android-app-problem/688/4 "2021-03-02T21:21:32Z")

</div>

I’ll defer to @mstenta to correct me if I’m wrong, but you may need to set up an https reverse proxy if you’re hosting on your local network and want to connect to [https://farmos.app](https://farmos.app) or the Android APK:

[https://farmos.org/development/configure-local-https-reverse-proxy/](https://farmos.org/development/configure-local-https-reverse-proxy/)

---

<div class="post-metadata">

### Author: ![darrenjlobb](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@darrenjlobb](https://farmos.discourse.group/u/darrenjlobb)
#### Post date: [March 2, 2021, 9:40pm UTC](https://farmos.discourse.group/t/android-app-problem/688/5 "2021-03-02T21:40:36Z")

</div>

Hm, Just updated to latest version as wondered if that was effecting it, but sadly not…

Can anyone confirm if the reverse proxy is required given I can use the [https://localhostname](https://localhostname) and browse FarmOS no problem…

---

<div class="post-metadata">

### Author: ![darrenjlobb](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@darrenjlobb](https://farmos.discourse.group/u/darrenjlobb)
#### Post date: [March 2, 2021, 9:42pm UTC](https://farmos.discourse.group/t/android-app-problem/688/6 "2021-03-02T21:42:30Z")

</div>

Just tried using the link [https://farmos.app](https://farmos.app) in my pc browser, and then get the error saying that OAuth isn’t enabled on my FarmOS install…but when I go to the page to enable it, it is already enabled…

---

<div class="post-metadata">

### Author: ![jgaehring](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/jgaehring/32/927_2.png) [@jgaehring](https://farmos.discourse.group/u/jgaehring)
#### Post date: [March 2, 2021, 9:50pm UTC](https://farmos.discourse.group/t/android-app-problem/688/7 "2021-03-02T21:50:59Z")

</div>

Just to confirm, you’ve specifically enabled the “farmOS Client (Field Kit)” client, as shown below, correct?

![image](https://global.discourse-cdn.com/free1/uploads/farm_os/original/1X/3a0a53861e66bf8b1fe511b7aaf0e29652396372.png)

---

<div class="post-metadata">

### Author: ![darrenjlobb](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@darrenjlobb](https://farmos.discourse.group/u/darrenjlobb)
#### Post date: [March 2, 2021, 9:52pm UTC](https://farmos.discourse.group/t/android-app-problem/688/8 "2021-03-02T21:52:48Z")

</div>

I have now… Which now means when I access via browser to the .app site, I can login…but still no good on the phone…

---

<div class="post-metadata">

### Author: ![jgaehring](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/jgaehring/32/927_2.png) [@jgaehring](https://farmos.discourse.group/u/jgaehring)
#### Post date: [March 2, 2021, 9:55pm UTC](https://farmos.discourse.group/t/android-app-problem/688/9 "2021-03-02T21:55:03Z")

</div>

Ok, that’s something. 🙂

When you’re accessing farmos.app in your PC browser to your farmOS server, is that the same machine that is running your server?

---

<div class="post-metadata">

### Author: ![darrenjlobb](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@darrenjlobb](https://farmos.discourse.group/u/darrenjlobb)
#### Post date: [March 2, 2021, 9:59pm UTC](https://farmos.discourse.group/t/android-app-problem/688/10 "2021-03-02T21:59:44Z")

</div>

No, its hosted on a virtual server in my rack…

Just been playing, If i go on chrome on my android phone, and go to farmos.app…I can login / works fine…but if i use the home screen shortcut as from the apk, it doesn’t work…

---

<div class="post-metadata">

### Author: ![jgaehring](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/jgaehring/32/927_2.png) [@jgaehring](https://farmos.discourse.group/u/jgaehring)
#### Post date: [March 2, 2021, 10:05pm UTC](https://farmos.discourse.group/t/android-app-problem/688/11 "2021-03-02T22:05:39Z")

</div>

Hmm, you might just try removing the shortcut and trying “Install app” again from the Chrome main menu, or clicking the “Add farmOS to Home screen” banner, if that pops up.

 ![image](https://global.discourse-cdn.com/free1/uploads/farm_os/original/1X/b54a06248c328e7c8d0f61902d0934e9355f956a.png)

---

<div class="post-metadata">

### Author: ![Symbioquine](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/symbioquine/32/284_2.png) [@Symbioquine](https://farmos.discourse.group/u/Symbioquine)
#### Post date: [March 3, 2021, 3:16am UTC](https://farmos.discourse.group/t/android-app-problem/688/12 "2021-03-03T03:16:56Z")

</div>

My understanding is that proceeding despite a browser certificate error is not the same as adding that certificate to your trust store - either browser or OS level.

Regardless of whether you choose to go with the PWA or APK, I’d recommend explicitly trusting the local CA certificate that you’re using to generate your certificates. For the PWA that would probably mean adding the certificate to your browser’s trust store, and for the APK it would probably mean adding it to the Android trust store. You should be able to find lots of tutorials for how to do that on various systems. e.g. [FAQ/ImportRootCert - CAcert Wiki](http://wiki.cacert.org/FAQ/ImportRootCert?action=show&redirect=ImportRootCert#Android_Phones_.26_Tablets)

---

<div class="post-metadata">

### Author: ![mstenta](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/mstenta/32/4_2.png) [@mstenta](https://farmos.discourse.group/u/mstenta)
#### Post date: [March 3, 2021, 11:56am UTC](https://farmos.discourse.group/t/android-app-problem/688/13 "2021-03-03T11:56:24Z")

</div>

Yea, following on what @Symbioquine said - when you “accept” the SSL certificate in your browser (to tell Chrome that you trust it, even though Chrome doesn’t recognize the issuer) - that “acceptance” only applies to the browser/session/computer you accepted it from.

Whenever a third-party application needs to connect, it will run into the same problem. This is probably why you’re having trouble in other contexts - it may not give you the option to “accept” the certificate in an APK version, and maybe the same is true in a PWA that is “installed to homescreen” (I’m not sure how the browser manages the session in that case - it may be a different session than the phone’s browser itself).

A good example of this problem is `curl`, which is a command line tool for sending requests. If you have a self-signed certificate, `curl` will not let you send the request, and will instead show an error that the SSL is insecure. The only way to send the request is to add the `-k` flag, which says “allows insecure connections”. That’s basically what you’re doing when you “accept” it in a browser as well. Field Kit uses a library called Axios for HTTP requests, and similarly that library provides a special flag to allow insecure connections (see [How to ignore SSL issues · Issue #535 · axios/axios · GitHub](https://github.com/axios/axios/issues/535)). Field Kit does not include this flag (nor should it). So I’m actually surprised that it worked for you in ANY context - but that just suggests to me that your browser is remembering that you accepted it, when it was done in the same computer/session/context. That’s just a guess though, and I could be missing something… in either case I think the solution is to either:

a) create a real SSL certificate  
b) add the self-signed cert to your trust store (as @Symbioquine suggested)

Hope that helps!

FYI: A reverse proxy is not required. That’s just a method for serving farmOS with HTTPS, but it sounds like you’re already doing that. So I assume you either configured Apache SSL, or you already have a reverse proxy of some kind? 🙂

---

<div class="post-metadata">

### Author: ![darrenjlobb](https://avatars.discourse-cdn.com/v4/letter/d/ecb155/32.png) [@darrenjlobb](https://farmos.discourse.group/u/darrenjlobb)
#### Post date: [March 3, 2021, 5:14pm UTC](https://farmos.discourse.group/t/android-app-problem/688/14 "2021-03-03T17:14:07Z")

</div>

As a follow up to this, I removed the “app” from phone…and just went on chrome, and used the “install app” feature, and it then works just fine…

Yes, I have apache setup with SSL, but for servers hosted locally, I’m not sure that its possible to create a real SSL certificate? Unless I open it to the web, and point a domain at it?

---

<div class="post-metadata">

### Author: ![Symbioquine](https://yyz2.discourse-cdn.com/free1/user_avatar/farmos.discourse.group/symbioquine/32/284_2.png) [@Symbioquine](https://farmos.discourse.group/u/Symbioquine)
#### Post date: [March 3, 2021, 7:51pm UTC](https://farmos.discourse.group/t/android-app-problem/688/15 "2021-03-03T19:51:36Z")

</div>

Yeah, you have to have a real domain to have a real certificate, but you don’t have to open it up to the web to get a certificate that is automatically trusted by the majority of browsers/OSs Any strategy that allows you to provision a valid certificate for a domain you own could be used, as long as you can get the certificates onto the local server machine and some form of DNS the point the domain/subdomain at that server.

Taking things a bit further, if you want free and automated provisioning of those certificates, the ACME protocol that [Let’s Encrypt](https://en.wikipedia.org/wiki/Let%27s_Encrypt) uses supports something called dns01 validation. All that is required to pass the “challenge” for dns01 validation - proving you own the domain and can be granted a certificate - is some special public DNS entries that the ACME protocol will generate. This means that you can use tools like [Certbot](https://certbot.eff.org/), [Dehydrated](https://github.com/dehydrated-io/dehydrated), or [cert-manager](https://cert-manager.io/) to provision certificates as long as the place you’re provisioning them has outbound internet access.

As a more concrete example, you could spin up a [docker-dehydrated](https://github.com/matrix-org/docker-dehydrated) container along side your farmOS installation and manually pass the dns01 challenge by inserting some custom (public) DNS records Dehydrated will provide. After which Dehydrated should keep renewing the certificates for you - at worst occassionally requiring you to re-verify with a new DNS challenge. You could then add additional DNS entries either via the public DNS or on your local network/clients to point at the local network IP of your server.
