Android 14 or below "collect can't connect securely to the server"

1. What is the issue? Please be detailed.

We have been collecting forms from ODK Collect to a local ODK Central install. A few weeks ago, out IT department updated the SSL certificate on the ODK Central IP. Now, the site works fine, and devices running Android 15 or above are working as expected, but devices with Android 14 or below are returning the error “collect can't connect securely to the server”. The URLs are fine; we can use the same user QR code on an Android 14 or lower and an Android 15 or above and see different results. The URL connects as expected without a certificate warning from the Android 14 or lower device browsers as well. So the issue is limited to ODK Collect.

2. What steps can we take to reproduce this issue?

It’s consistently reproducible.

3. What have you tried to fix the issue?

We’ve tried testing to determine any other factor and talked to our IT SSL experts to determine what might have changed recently.

4. Upload any forms or screenshots you can share publicly below.

You likely have a root cert in your chain that isn't trusted on Android 14.

Here's what we use on our servers. Compare with yours and you might get a hint what might be wrong.

Thank you! We’ll keep looking and share if we figure it out.