diff --git a/core/java/android/app/admin/DevicePolicyManager.java b/core/java/android/app/admin/DevicePolicyManager.java
index 930717b975551..3bafdc44563c8 100644
--- a/core/java/android/app/admin/DevicePolicyManager.java
+++ b/core/java/android/app/admin/DevicePolicyManager.java
@@ -6159,13 +6159,22 @@ public class DevicePolicyManager {
// STOPSHIP(b/174298501): clarify the expected return value following generateKeyPair call.
/**
- * Called by a device or profile owner, or delegated certificate installer, to query whether a
- * certificate and private key are installed under a given alias.
+ * This API can be called by the following to query whether a certificate and private key are
+ * installed under a given alias:
+ *
+ * - Device owner
+ * - Profile owner
+ * - Delegated certificate installer
+ * - Credential management app
+ *
+ *
+ * If called by the credential management app, the alias must exist in the credential
+ * management app's {@link android.security.AppUriAuthenticationPolicy}.
*
* @param alias The alias under which the key pair is installed.
* @return {@code true} if a key pair with this alias exists, {@code false} otherwise.
- * @throws SecurityException if the caller is not a device or profile owner or a delegated
- * certificate installer.
+ * @throws SecurityException if the caller is not a device or profile owner, a delegated
+ * certificate installer or the credential management app.
* @see #setDelegatedScopes
* @see #DELEGATION_CERT_INSTALL
*/
diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java
index 1a2eee06da4f2..7e6e2fa5300a7 100644
--- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java
+++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java
@@ -5488,7 +5488,8 @@ public class DevicePolicyManagerService extends BaseIDevicePolicyManager {
@Override
public boolean hasKeyPair(String callerPackage, String alias) {
final CallerIdentity caller = getCallerIdentity(callerPackage);
- Preconditions.checkCallAuthorization(canManageCertificates(caller));
+ Preconditions.checkCallAuthorization(canManageCertificates(caller)
+ || isCredentialManagementApp(caller, alias));
return mInjector.binderWithCleanCallingIdentity(() -> {
try (KeyChainConnection keyChainConnection =