From a65707d3f3a2498bda9aba63afb7d789f861f676 Mon Sep 17 00:00:00 2001
From: Alex Klyubin
Date: Wed, 13 Apr 2016 15:33:53 -0700
Subject: [PATCH] Clarify how to replace cert generated by Android Keystore.
This updates Android Keystore developer documentation to clarify how
to replace the self-signed certificate create by Android Keystore when
it generates a new key pair. Some developers are attempting to use
KeyStore.setCertificateEntry which is the wrong method for this. The
correct method is KeyStore.setKeyEntry.
Bug: 28152878
Change-Id: I306447b7792ecad5fbb49bd691a57bedb5207003
---
docs/html/training/articles/keystore.jd | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/docs/html/training/articles/keystore.jd b/docs/html/training/articles/keystore.jd
index aa1ed0acb3a7e..026f7a0d87850 100644
--- a/docs/html/training/articles/keystore.jd
+++ b/docs/html/training/articles/keystore.jd
@@ -152,8 +152,10 @@ and {@link java.security.KeyPairGenerator} or
Generating a new {@link java.security.PrivateKey} requires that
you also specify the initial X.509 attributes that the self-signed
- certificate will have. You can replace the certificate at a later
- time with a certificate signed by a Certificate Authority.
+ certificate will have. You can use
+ {@link java.security.KeyStore#setKeyEntry(String, java.security.Key, char[], java.security.cert.Certificate[]) KeyStore.setKeyEntry}
+ to replace the certificate at a later time with a certificate signed
+ by a Certificate Authority (CA).
To generate the key, use a {@link java.security.KeyPairGenerator}
with {@link android.security.KeyPairGeneratorSpec}: