A small, native Holo-themed Android app that automates the manual
"update the system CA trust store" process that shows up in
r/androidafterlife guides for keeping very old Android devices able to
reach modern HTTPS sites. It does, with a tap, what the manual tutorial
does over adb:
mount -o rw,remount,rw /system
cp <new cert files> /system/etc/security/cacerts/
chmod / chown the new files
mount -o ro,remount,ro /system
reboot
Requires a rooted device. It will not work, and will tell you so
plainly, on a non-rooted device. minSdkVersion is 14 (Android 4.0 ICS).
- Checks for root (
su) on launch. - Lets you choose a certificate source:
- Download automatically — pulls the current CA bundle straight
from Google's public
android_system/ca-certificatessource archive. - Import from local storage — pick a
.tar.gz/.tgz,.zip, or a single.pem/.crt/.cer/.derfile yourself (useful on devices whose browser/TLS stack is too outdated to reach the download URL — exactly the chicken-and-egg problem this app exists to fix).
- Download automatically — pulls the current CA bundle straight
from Google's public
- Extracts the certificate files itself (hand-rolled tar/zip readers —
no external libraries, no
tarbinary required on the device). - Runs the actual install as a single root shell session: backs up your
existing certs to a timestamped folder under
/system/etc/security/first, then copies in the new ones, fixes permissions/ownership, and remounts/systemread-only again. - Shows a live terminal-style log of every command and its output (tap "View Terminal Log").
- Offers a one-tap reboot once the install finishes.
CertUpdater/
├── app/
│ ├── build.gradle
│ └── src/main/
│ ├── AndroidManifest.xml
│ ├── java/com/androidafterlife/certupdater/
│ │ ├── MainActivity.java UI + orchestration
│ │ ├── LogActivity.java terminal-style output viewer
│ │ ├── LogStore.java shared in-memory log buffer
│ │ ├── RootUtils.java su detection + command execution
│ │ ├── CertDownloader.java HTTP download of the cert bundle
│ │ ├── ArchiveExtractor.java tar.gz / zip / single-cert import
│ │ └── CertInstaller.java builds & runs the install script
│ └── res/
│ ├── layout/ activity_main.xml, activity_log.xml
│ ├── values/ styles.xml (Theme.Holo), strings, colors
│ └── drawable/ ic_launcher.xml
├── build.gradle
├── settings.gradle
└── gradle.properties
No AndroidX, no support library, no third-party dependencies at all —
just the plain Android framework SDK. That's deliberate: it's what lets
android:Theme.Holo render as the real, native holographic theme instead
of being overridden by AppCompat/Material, and it keeps the app buildable
all the way down to API 14 without any library-version conflicts.
You'll need Android Studio (or just the command-line SDK tools + a JDK).
Easiest path — Android Studio:
File → Open, select theCertUpdaterfolder.- Let it sync (it will fetch the Gradle wrapper and Android SDK platform 28 automatically on first sync if you don't already have them).
Build → Build Bundle(s)/APK(s) → Build APK(s), or just hit Run with a device/emulator connected.
Command line, if you already have the Gradle wrapper jar and an
Android SDK installed and ANDROID_HOME set:
cd CertUpdater
gradle wrapper --gradle-version 7.6.4 # only needed once, to generate gradlew/gradlew.bat
./gradlew assembleDebug
The APK lands in app/build/outputs/apk/debug/app-debug.apk.
- Install the APK, grant your root manager (Magisk/SuperSU/etc.) the prompt it will show on first launch.
- Choose "Download automatically" first; if that fails (old TLS stack
can't reach the URL), fall back to "Import from local storage" —
download
files.tar.gzyourself fromhttps://android.googlesource.com/platform/system/ca-certificates/+archive/refs/heads/main/files.tar.gzon a modern computer/phone and copy it onto the device. - Tap Update Certificates Now, watch the status line (or the full terminal log), then Reboot Device once it reports success.
- A full backup of the existing
/system/etc/security/cacerts/directory is made automatically, to a sibling..._backup_<timestamp>folder, before anything is overwritten. If something looks wrong after reboot, you can restore it manually the same way (remount rw, copy back, remount ro) using any root file manager or terminal app. - Modifying
/systemon an unsupported/aging device always carries some risk. Make sure you have a way to recover the device (TWRP/custom recovery backup, etc.) before doing this on anything you can't easily re-flash. - The app never disables SELinux, never requests broad "device admin"
powers, and only ever talks to
android.googlesource.comover HTTPS for the optional auto-download.

