The situation on Android is particularly unfortunate. The Android folks have decided that user-added CAs are not exposed to apps unless they explicitly opt in, so nothing works out-of-the box.
I personally don't see the threat model they are addressing, but of course there's the "nice" side effect that it stops a lot of privacy research.
Comments
Some apps pin their certs, which may break them with Man-In-The-Middle proxy this tool uses.
Author: please consider adding a blurb about that on your page.
The situation on Android is particularly unfortunate. The Android folks have decided that user-added CAs are not exposed to apps unless they explicitly opt in, so nothing works out-of-the box. I personally don't see the threat model they are addressing, but of course there's the "nice" side effect that it stops a lot of privacy research.