diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java index 579f9126b3189..d4d3321d37a45 100644 --- a/core/java/android/app/admin/DevicePolicyManager.java +++ b/core/java/android/app/admin/DevicePolicyManager.java @@ -6169,13 +6169,22 @@ public class DevicePolicyManager { // STOPSHIP(b/174298501): clarify the expected return value following generateKeyPair call. /** - * Called by a device or profile owner, or delegated certificate installer, to query whether a - * certificate and private key are installed under a given alias. + * This API can be called by the following to query whether a certificate and private key are + * installed under a given alias: + * + * + * If called by the credential management app, the alias must exist in the credential + * management app's {@link android.security.AppUriAuthenticationPolicy}. * * @param alias The alias under which the key pair is installed. * @return {@code true} if a key pair with this alias exists, {@code false} otherwise. - * @throws SecurityException if the caller is not a device or profile owner or a delegated - * certificate installer. + * @throws SecurityException if the caller is not a device or profile owner, a delegated + * certificate installer or the credential management app. * @see #setDelegatedScopes * @see #DELEGATION_CERT_INSTALL */ diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index 10b33b3a2377d..f2b452948384a 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -5482,7 +5482,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager { @Override public boolean hasKeyPair(String callerPackage, String alias) { final CallerIdentity caller = getCallerIdentity(callerPackage); - Preconditions.checkCallAuthorization(canManageCertificates(caller)); + Preconditions.checkCallAuthorization(canManageCertificates(caller) + || isCredentialManagementApp(caller, alias)); return mInjector.binderWithCleanCallingIdentity(() -> { try (KeyChainConnection keyChainConnection =