Posts

Showing posts with the label certification

Dig into Https client connection in Android

Dig into Https client connection in Android Table of Contents reference resources Java Keytool Certificate formats Use Https in Android Client Java SSLContext Two ways SSL verification TLSDemo 1 reference resources http://developer.android.com/training/articles/security-ssl.html http://ogrelab.ikratko.com/using-android-volley-with-self-signed-certificate/ http://stackoverflow.com/questions/2138940/import-pem-into-java-key-store http://stackoverflow.com/questions/3685548/java-keytool-easy-way-to-add-server-cert-from-url-port 2 Java Keytool Java keystore is like a database which store certificates and private keys and protect them by a password maybe. There are at least three format s of that, JKS, PKCS12, JCEKS, and many more. But in this tutorial, I only consider two formats of that JKS which is the Java's default format and BKS which is the Android's default format. How to import a certificate to the BKS style KeyStore? First step was to pr...

Android's Package Management System

Image
Android's Package Management System Table of Contents How to resign an android app? How to install an android apk? android package management system. How to get an app's certification? 1 How to resign an android app? Android apk's digital signature strategy just employs the java's jar package method. So We can use java's keystore and jarsigner tools to sign an apk. And the first step is to generate a valid certification: make your own keystore keytool -genkey -v -keystore iboxpay.keystore -alias ibox -keyalg RSA -keysize 2048 -validity 100000 please remember the store password and key password, I always set them the same one. then before to resign an apk, I should remove its original signature first. remove apk's digital signature zip -d whatever.apk "META-INF/*" After that, I can sign that apk by our own certification. sign apk by jarsigner jarsigner -verbose -keystore iboxpay.keystore -storepass 123456 what...