15a2d77a0f
Samsung One UI 7 (Android 16) silently rejects TLS connections that use a no-op X509TrustManager which accepts all certificates. This breaks Namecoin resolution on all Samsung devices running One UI 7, including Galaxy A15 (SM-A156E) and Galaxy S24 Ultra (SM-S938B). Replace trustAllSslFactory() with pinnedSslFactory() that: - Pins the actual self-signed certificates of known ElectrumX servers - Also includes system CA certificates for servers with real certs - Uses a proper TrustManagerFactory chain that Samsung Knox accepts Additional OEM compatibility hardening: - Cache the SSLSocketFactory (avoid expensive rebuild per connection) - Request TLSv1.2 explicitly (Xiaomi MIUI/HyperOS and OnePlus ColorOS Conscrypt forks may default to TLS 1.0 for raw socket upgrades) - Enforce TLSv1.2+ enabled protocols on the SSLSocket - KeyStore fallback to PKCS12 if default type fails (Xiaomi) - Defensive try/catch on system CA cert re-insertion (some OEMs return certs that cannot be added to a new KeyStore) Tested on Android 16 (API 36) emulator — all ElectrumX servers connect (hostname, IP-address, factory reuse) and .bit resolution works E2E. Pinned certs: - electrumx.testls.space:50002 (expires 2027-05-04) - nmc2.bitcoins.sk:57002 (expires 2030-10-22)