Google play app signing process certificates

Viewed 1588

I am trying to understand the signing process with the Play App Signing. Hence couple of questions.

  1. I am using google maps API, why I need to add SHA-1 certificate fingerprint of App signing key certificate on the console? Why I cant use that SHA 1 which is generated on my pc locally?
  2. What I need to do with the provate_key.pepk that I generated from release?
  3. What is the purpose of deployment_cert.der?
  4. What is the purpose of upload_cert.der?

Can you please explain me the correct process of signing an app and how to use it?

Also here

Existing apps->Step 2->5 Syas: Select the export and upload option that best suits your release process and upload an existing app signing key.

I do not see an option for upload an existing app signing key...

1 Answers

The app signing process in Play store is demonstrated below,

enter image description here

Google Play signing uses two keys.

  • Upload key
  • App signing key

Upload Key

TL;DR: Google use this key to identify the uploader of the apk/bundle

This key is used to sign the apk/bundle when uploading to the Play Store. This key let Android know the app updates are authentic and comes from the original author.

upload_cert.der is the public key for the Upload key.

App Signing Key

This key is used to sign the APKs that are installed in the user's device. You can have Google manage the key

deployment_cert.der is the public key of the app signing key.

So answering your questions,

  1. if your device is running app signed with upload key (developer key), the fingerprints in API console should match with the upload key, vice versa if the app in your device is signed with App Signing key, you need to have the fingerprints of the same. Commonly the signed apks/bundles built from android studio are signed with the upload key you choose. The app installs from the Play Store uses App Signing Key.

  2. Keep it safe, this is required for Google to identify the author when pushing updates.

  3. See the App Signing Key part

  4. See the Upload Key part

Related