> For the complete documentation index, see [llms.txt](https://pcastagnaro.gitbook.io/pentest-bug-bounty-resources/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pcastagnaro.gitbook.io/pentest-bug-bounty-resources/pentest-bounty-resources/mobile/android/sast.md).

# APK Certificates

## Generating An Android Certificate

When decompiling an android application and compiling it back, you will need to sign the app, and if you don’t sign it, the Application will not be installed on the user device.

There are different ways of generating a certificate but the easiest and universal one is using `keytool`.

{% tabs %}
{% tab title="Bash" %}

```bash
keytool -genkey -v -keystore KeyStoreName -alias KeyStoreAlias -keyalg RSA -keysize 2048 -validity 365
```

{% endtab %}
{% endtabs %}

{% hint style="info" %}
`-keystore KeyStoreName` is the keystore name

`-alias KeyStoreAlias` is the certificate alias name, which after you use it will be added to `META-INF` folder

`-keysize 2048` You can use 4096 size, but there are issues regarding that from devices or so.

`-validity 365` Validity in days
{% endhint %}

![Generating a Certificate](https://532189072-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lt8335BPUBXjq3iC572%2F-MBoWgaYzKoFbcL-IaFF%2F-MBoXKNCTvQSkftU2vBT%2Fimage.png?alt=media\&token=df789230-a2a5-40d5-9f67-76abc78715cf)

## Signing An Android Applicaiton

### JarSigner

{% hint style="danger" %}
It's important to note your APK (`YourAPK_unsigned.apk`) will be overwritten. If you want to keep an unsigned copy, please first create a copy of`YourAPK_unsigned.apk`
{% endhint %}

```
jarsigner -verbose -sigalg SHA1withRSA -digestalg SHA1 -keystore KeyStoreName YourAPK_unsigned.apk KeyStoreAlias
mv YourAPK_unsigned.apk YourAPK_signed.apk
```

{% hint style="info" %}
`-sigalg` is the signature algorithm used. There are some apps using MD5 but use SHA1 as when you are verifying the app it will tell you the hashing algorithm used and how weak the algorithm used is.

`-keystore KeyStoreName` is the name of the keystore name used when generating the certificate

`YourAPK_unsigned.apk` is the name of the app to be sign. Note: if you used MD5, the application will be treated as an unsign app because the algorithm used to sign the App is weak.

`KeyStoreAlias` is the alias name of the certificate used when creating the certificate.
{% endhint %}

![](https://532189072-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lt8335BPUBXjq3iC572%2F-MBoWgaYzKoFbcL-IaFF%2F-MBo_LuXPXaKEnz26TO9%2Fimage.png?alt=media\&token=2c7ebde0-f642-478f-b3af-409692211715)

![](https://532189072-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lt8335BPUBXjq3iC572%2F-MBoWgaYzKoFbcL-IaFF%2F-MBo_UxPHC7CfZcoIe_7%2Fimage.png?alt=media\&token=b56cd61a-278e-4fea-96c7-a145f32dec84)

### APKSigner

#### **Install APKSigner**

```
sudo apt-get apksigner
```

#### **Sign the APK**

{% hint style="danger" %}
It's important to note your APK (`YourAPK_unsigned.apk`) will be overwritten. If you want to keep an unsigned copy, please first create a copy of`YourAPK_unsigned.apk`
{% endhint %}

```
apksigner sign --ks KeyStoreName YourAPK_unsigned.apk
mv YourAPK_unsigned.apk YourAPK_signed.apk
```

![](https://532189072-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lt8335BPUBXjq3iC572%2F-MBoWgaYzKoFbcL-IaFF%2F-MBob8hrArNVI1R1vYiH%2Fimage.png?alt=media\&token=dfccb3a5-84b5-4cdb-8350-fc3425bdbb62)

```
apksigner verify --verbose YourAPK_signed.apk
```

![](https://532189072-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Lt8335BPUBXjq3iC572%2F-MBoWgaYzKoFbcL-IaFF%2F-MBobceUCllrSC9jyHfA%2Fimage.png?alt=media\&token=65a6489f-fd63-454f-8c51-215df3c099ce)
