I an trying to set up SSL on a Ktor Server on Android. The certificates are loaded at runtime, so i am using a AndroidKeyStore to store them. However, ktor is unable to initialize. It seems like AndroidKeyStore is implented to throw an exception whenever a KeyStorePassword is provided. So to add the key to AndroidKeyStore, i have to provide a null password like so keystore.setKeyEntry(alias, keyPair.private, null, arrayOf(certificate))
But when i then pass the keystore to ktor, i get a NullPointerException, because ktor tries to interact with the password when it is null. My ktor setup looks like
embeddedServer(Netty, applicationEngineEnvironment {
sslConnector(
keyStore = keyStore,
keyAlias = alias,
keyStorePassword = { charArrayOf() },
privateKeyPassword = { charArrayOf() }
)
})
I have tried both versions 2.0.3 and 1.6,8 of Ktor, and am using Android sdk version 28
So my queston is - is there any way to use AndroidKeyStore with ktor, and if not, what would be the best alternative with regards to security?