From a65707d3f3a2498bda9aba63afb7d789f861f676 Mon Sep 17 00:00:00 2001 From: Alex Klyubin Date: Wed, 13 Apr 2016 15:33:53 -0700 Subject: [PATCH] Clarify how to replace cert generated by Android Keystore. This updates Android Keystore developer documentation to clarify how to replace the self-signed certificate create by Android Keystore when it generates a new key pair. Some developers are attempting to use KeyStore.setCertificateEntry which is the wrong method for this. The correct method is KeyStore.setKeyEntry. Bug: 28152878 Change-Id: I306447b7792ecad5fbb49bd691a57bedb5207003 --- docs/html/training/articles/keystore.jd | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/docs/html/training/articles/keystore.jd b/docs/html/training/articles/keystore.jd index aa1ed0acb3a7e..026f7a0d87850 100644 --- a/docs/html/training/articles/keystore.jd +++ b/docs/html/training/articles/keystore.jd @@ -152,8 +152,10 @@ and {@link java.security.KeyPairGenerator} or

Generating a new {@link java.security.PrivateKey} requires that you also specify the initial X.509 attributes that the self-signed - certificate will have. You can replace the certificate at a later - time with a certificate signed by a Certificate Authority.

+ certificate will have. You can use + {@link java.security.KeyStore#setKeyEntry(String, java.security.Key, char[], java.security.cert.Certificate[]) KeyStore.setKeyEntry} + to replace the certificate at a later time with a certificate signed + by a Certificate Authority (CA).

To generate the key, use a {@link java.security.KeyPairGenerator} with {@link android.security.KeyPairGeneratorSpec}: