2026-09-16 20:25 UTC
If you are like me and run your own private, Nextcloud server that isn't exposed to the internet and want to sync podcasts between your phone and computer using gPodder sync, you'll quickly discover that no podcast client will talk to a server with a self-signed certificate. Not because it's technically dangerous, but because the developers have chosen not to support it. A single checkbox would fix it. They've been asked. They won't do it. Why? Skip to the last paragraph.
And yeah, with the amount of work I had to put it - I'm mad. :neofox_floof_explode:
This pattern repeats across every app, every platform, and the Android operating system itself. The consistent push from podcast apps, Google (Android) and the Linux desktop ecosystem is toward public certificate authorities and away from privately managed infrastructure. The people who suffer is anyone who wants to run their own server without exposing it to the internet.
Adding a certificate to Ubuntu's system trust store is straightforward and works immediately for natively installed applications. Flatpak (increasingly pushed as the Linux desktop standard) is a different problem entirely. Flatpak isolates apps from the host system, and the mechanism that's supposed to bridge host certificates into that sandbox is broken.
For several versions, Android has had a deliberate policy to hamper users to install their own certificates. It's a pain. App developers can opt in to trusting user-installed certificates with a one-line configuration change. Most haven't. AntennaPod hasn't.
None of this is technically insurmountable. But the cumulative friction across every layer... The apps, the OS, the desktop packaging format, the server appliance all pushes in the same direction: Self-hosting with your own certificates is made difficult everywhere, simultaneously, by parties who agree on the plausible-sounding security justification:
"The only safe option is to have a publicly exposed server with a CA-signed certificate". Like that's safer than accessing a server with a manually verified certificate through a closed VPN mesh network.
#selfhosted #selfhosting #self-hosted #self-hosting #antennapod #flatpak #gpodder #nextcloud #nextcloudpi
Replies (1)
-
@japhacake@social.linux.pizza 2026-09-16 21:32
@sarah@sosial.link you could selfhost your own internal CA like smallstep or XCA, then install the root cert to all your devices.