# SmartTube TLS Provider Configuration with Conscrypt: Implementation Guide

> Learn how to configure Conscrypt as the TLS provider for SmartTube. This guide details the implementation for enhanced network security and performance.

- Repository: [Yuriy L/SmartTube](https://github.com/yuliskov/SmartTube)
- Tags: how-to-guide
- Published: 2026-09-14

---

**SmartTube optionally replaces the default Android TLS stack with Conscrypt by exposing a user toggle in Network settings that persists to `NetworkData` and conditionally inserts the provider at priority position 1 during `MainApplication.onCreate()`.**

SmartTube, the open-source Android TV YouTube client developed by yuliskov/SmartTube, implements an optional **TLS provider configuration with Conscrypt** to modernize encryption support on legacy devices. This architecture allows users to upgrade from outdated OpenSSL implementations to Google's maintained security provider, ensuring TLS 1.3 compatibility and stronger cipher suites while maintaining backward compatibility with Android 10+ systems that already include Conscrypt.

## How Conscrypt Integration Works in SmartTube

The implementation follows a three-stage architecture spanning the UI layer, persistent storage, and application initialization.

### User-Controlled Toggle in GeneralSettingsPresenter

The entry point resides in `GeneralSettingsPresenter.appendConscrypt()` (lines 67-74), which appends a switch to the Network settings UI. When toggled, the option immediately persists the choice via `mNetworkData.setConscryptEnabled()` and flags `mRestartApp = true` to ensure the provider loads on next launch.

```java
// In GeneralSettingsPresenter.appendConscrypt()
options.add(UiOptionItem.from(
        getContext().getString(R.string.enable_conscrypt),
        getContext().getString(R.string.enable_conscrypt_desc),
        option -> {
            // Persist the user choice
            mNetworkData.setConscryptEnabled(option.isSelected());
            // Restart required to re-initialise provider
            mRestartApp = true;
        },
        // Initial state (read from preferences)
        mNetworkData.isConscryptEnabled()));

```

### Persistent Storage via NetworkData

The `NetworkData` class (lines 22-28) manages the boolean flag using the generic `DataSaverBase` mechanism. The getter `isConscryptEnabled()` and setter `setConscryptEnabled()` provide the API surface for checking and updating the preference.

```java
boolean useConscrypt = NetworkData.instance(context).isConscryptEnabled();
if (useConscrypt) {
    // Conscrypt has already been inserted at priority 1 during app start.
    // Any subsequent HTTPS connections will automatically use it.
}

```

### Runtime Provider Insertion in MainApplication

The critical initialization occurs in `MainApplication.onCreate()`. The code instantiates `Conscrypt.newProvider()` at line 71, then conditionally inserts it at priority position 1 (lines 76-81) only if `NetworkData.instance(this).isConscryptEnabled()` returns true.

```java
Provider conscryptProvider = null;
try {
    // Load native Conscrypt implementation (fails gracefully on unsupported devices)
    conscryptProvider = Conscrypt.newProvider();
} catch (Throwable ignored) {}

if (conscryptProvider != null && NetworkData.instance(this).isConscryptEnabled()) {
    try {
        // Insert at position 1 so it overrides default providers
        Security.insertProviderAt(conscryptProvider, 1);
    } catch (Throwable ignored) {}
}

```

## Why SmartTube Uses Conscrypt on Older Android Versions

Conscrypt offers **TLS 1.3 support**, **modern cipher suites**, and a fully audited **OpenSSL-based implementation** that outperforms legacy Android security providers. While Android 10 (API 29) and higher ship Conscrypt as the system default, older Android TV devices rely on outdated OpenSSL libraries that may lack critical security patches.

According to the source code comments in `MainApplication` (lines 60-66), manual insertion is unnecessary on Android 10+ since the system already supplies Conscrypt. The early initialization—performed before any SharedPreferences or disk I/O—prevents class-loader quirks on certain Android TV devices that could trigger silent JNI linking errors (lines 67-69).

## Key Implementation Files and Methods

| Component | File Path | Role |
|-----------|-----------|------|
| **MainApplication** | [`/smarttubetv/src/main/java/com/liskovsoft/smartyoutubetv2/tv/ui/main/MainApplication.java`](https://github.com/yuliskov/SmartTube/blob/main//smarttubetv/src/main/java/com/liskovsoft/smartyoutubetv2/tv/ui/main/MainApplication.java) | Instantiates and conditionally registers the Conscrypt provider |
| **NetworkData** | [`/common/src/main/java/com/liskovsoft/smartyoutubetv2/common/prefs/NetworkData.java`](https://github.com/yuliskov/SmartTube/blob/main//common/src/main/java/com/liskovsoft/smartyoutubetv2/common/prefs/NetworkData.java) | Stores the `isConscryptEnabled` boolean flag |
| **GeneralSettingsPresenter** | [`/common/src/main/java/com/liskovsoft/smartyoutubetv2/common/app/presenters/settings/GeneralSettingsPresenter.java`](https://github.com/yuliskov/SmartTube/blob/main//common/src/main/java/com/liskovsoft/smartyoutubetv2/common/app/presenters/settings/GeneralSettingsPresenter.java) | Renders the UI toggle and handles user input |

## Summary

- **SmartTube TLS provider configuration with Conscrypt** is optional and user-controlled via the Network settings toggle managed by `GeneralSettingsPresenter`.
- The `NetworkData` class persists the boolean flag and provides the runtime check used during application startup.
- `MainApplication.onCreate()` instantiates `Conscrypt.newProvider()` and inserts it at security provider position 1 when enabled.
- This upgrade primarily benefits Android devices running API 28 and below; Android 10+ already uses Conscrypt as the system default.
- Initialization occurs early in the application lifecycle to avoid class-loader issues on Android TV hardware.

## Frequently Asked Questions

### What is Conscrypt and why does SmartTube use it?

Conscrypt is Google's Java Security Provider implementation based on OpenSSL. SmartTube uses it to provide **TLS 1.3 support** and modern encryption algorithms on older Android TV devices that ship with outdated OpenSSL versions lacking recent security patches. The integration ensures encrypted connections use the strongest available cipher suites regardless of the underlying Android version.

### How do I enable Conscrypt in SmartTube?

Navigate to **Settings > Network** in the SmartTube interface and toggle "Enable Conscrypt". Because `MainApplication.onCreate()` must insert the provider into the Java security list before any network connections initialize, the app requires a restart after enabling the option. The `GeneralSettingsPresenter` automatically sets `mRestartApp = true` when the toggle changes.

### Is Conscrypt enabled by default on Android 10+?

No manual configuration is required on Android 10 (API 29) and higher because the system already uses Conscrypt as the default TLS provider. As noted in the `MainApplication` source comments, the manual insertion logic exists primarily to benefit devices running Android 9 and earlier, where the legacy OpenSSL provider remains the system default.

### What happens if Conscrypt fails to load?

The implementation includes comprehensive silent error handling. If `Conscrypt.newProvider()` throws an exception during instantiation or `Security.insertProviderAt()` fails during registration, SmartTube catches the throwable and falls back to the system's default TLS implementation without crashing the application. This ensures compatibility with devices that may have broken native library support.