Android sdk signing app

Installing the Android SDK

Android Studio provides everything you need to start developing apps for Android, including the Android Studio IDE and the Android SDK tools.

If you didn’t download Android Studio, go download Android Studio now, or switch to the stand-alone SDK Tools install instructions.

Before you set up Android Studio, be sure you have installed JDK 6 or higher (the JRE alone is not sufficient)—JDK 7 is required when developing for Android 5.0 and higher. To check if you have JDK installed (and which version), open a terminal and type javac -version . If the JDK is not available or the version is lower than 6, go download JDK.

To set up Android Studio on Windows:

  1. Launch the .exe file you just downloaded.
  2. Follow the setup wizard to install Android Studio and any necessary SDK tools.

On some Windows systems, the launcher script does not find where Java is installed. If you encounter this problem, you need to set an environment variable indicating the correct location.

Select Start menu > Computer > System Properties > Advanced System Properties. Then open Advanced tab > Environment Variables and add a new system variable JAVA_HOME that points to your JDK folder, for example C:\Program Files\Java\jdk1.7.0_21 .

The individual tools and other SDK packages are saved outside the Android Studio application directory. If you need to access the tools directly, use a terminal to navigate to the location where they are installed. For example:

To set up Android Studio on Mac OSX:

  1. Unzip the downloaded zip file, android-studio-ide- -mac.zip .
  2. Drag and drop Android Studio into the Applications folder.
  3. Open Android Studio and follow the setup wizard to install any necessary SDK tools.

Depending on your security settings, when you attempt to open Android Studio, you might see a warning that says the package is damaged and should be moved to the trash. If this happens, go to System Preferences > Security & Privacy and under Allow applications downloaded from, select Anywhere. Then open Android Studio again.

  • Follow the links to install the SDK outside of the Android Studio directories.
  • The individual tools and other SDK packages are saved outside the Android Studio application directory. If you need access the tools directly, use a terminal to navigate into the location where they are installed. For example:

    To set up Android Studio on Linux:

    1. Unpack the downloaded Tar file, android-studio-ide- -linux.zip , into an appropriate location for your applications.
    2. To launch Android Studio, navigate to the android-studio/bin/ directory in a terminal and execute studio.sh .

    You may want to add android-studio/bin/ to your PATH environmental variable so that you can start Android Studio from any directory.

    If the SDK is not already installed, follow the setup wizard to install the SDK and any necessary SDK tools.

    Note: You may also need to install the ia32-libs, lib32ncurses5-dev, and lib32stdc++6 packages. These packages are required to support 32-bit apps on a 64-bit machine.

    Android Studio is now ready and loaded with the Android developer tools, but there are still a couple packages you should add to make your Android SDK complete.

    The stand-alone SDK Tools package does not include a complete Android development environment. It includes only the core SDK tools, which you can access from a command line or with a plugin for your favorite IDE (if available).

    If you didn’t download the SDK tools, go download the SDK now, or switch to the Android Studio install instructions.

    To get started on Windows:

    Your download package is an executable file that starts an installer. The installer checks your machine for required tools, such as the proper Java SE Development Kit (JDK) and installs it if necessary. The installer then saves the Android SDK Tools to a specified the location outside of the Android Studio directories.

    1. Double-click the executable ( .exe file) to start the install.
    2. Make a note of the name and location where you save the SDK on your system—you will need to refer to the SDK directory later when using the SDK tools from the command line.
    3. Once the installation completes, the installer starts the Android SDK Manager.

    To get started on Mac OSX:

    Unpack the ZIP file you’ve downloaded. By default, it’s unpacked into a directory named android-sdk-mac_x86 . Move it to an appropriate location on your machine, such as a «Development» directory in your home directory.

    Make a note of the name and location of the SDK directory on your system—you will need to refer to the SDK directory later when using the SDK tools from the command line.

    To get started on Linux:

    Unpack the .zip file you’ve downloaded. The SDK files are download separately to a user-specified directory.

    Make a note of the name and location of the SDK directory on your system—you will need to refer to the SDK directory later when using the SDK tools from the command line.

    Troubleshooting Ubuntu
    • If you need help installing and configuring Java on your development machine, you might find these resources helpful:
      • https://help.ubuntu.com/community/Java
      • https://help.ubuntu.com/community/JavaInstallation
    • Here are the steps to install Java:
      1. If you are running a 64-bit distribution on your development machine, you need to install additional packages first. For Ubuntu 13.10 (Saucy Salamander) and above, install the libncurses5:i386 , libstdc++6:i386 , and zlib1g:i386 packages using apt-get :

        For earlier versions of Ubuntu, install the ia32-libs package using apt-get :

        The Android SDK tools are now ready to begin developing apps, but there are still a couple packages you should add to make your Android SDK complete.

        Then, select which SDK bundle you want to install:

        Источник

        Adding SDK Packages

        By default, the Android SDK does not include everything you need to start developing. The SDK separates tools, platforms, and other components into packages you can download as needed using the Android SDK Manager. So before you can start, there are a few packages you should add to your Android SDK.

        To start adding packages, launch the Android SDK Manager in one of the following ways:

        • In Eclipse or Android Studio, click SDK Managerin the toolbar.
        • If you’re not using Eclipse or Android Studio:
          • Windows: Double-click the SDK Manager.exe file at the root of the Android SDK directory.
          • Mac/Linux: Open a terminal and navigate to the tools/ directory in the location where the Android SDK was installed, then execute android sdk .

        When you open the SDK Manager for the first time, several packages will be selected by default. Leave these selected, but be sure you have everything you need to get started by following these steps:

        Get the latest SDK tools

        As a minimum when setting up the Android SDK, you should download the latest tools and Android platform:

        1. Open the Tools directory and select:
          • Android SDK Tools
          • Android SDK Platform-tools
          • Android SDK Build-tools (highest version)
        2. Open the first Android X.X folder (the latest version) and select:
          • SDK Platform
          • A system image for the emulator, such as
            ARM EABI v7a System Image

        Get the support library for additional APIs

        The support library is required for:

        It also provides these popular APIs:

        The Android Support Library provides an extended set of APIs that are compatible with most versions of Android.

        Open the Extras directory and select:

        • Android Support Repository
        • Android Support Library

        Get Google Play services for even more APIs

        The Google Play services APIs provide a variety of features and services for your Android apps, such as:

        To develop with Google APIs, you need the Google Play services package:

        Open the Extras directory and select:

        • Google Repository
        • Google Play services

        Note: Google Play services APIs are not available on all Android-powered devices, but are available on all devices with Google Play Store. To use these APIs in the Android emulator, you must also install the the Google APIs system image from the latest Android X.X directory in the SDK Manager.

        Install the packages

        Once you’ve selected all the desired packages, continue to install:

        1. Click Install X packages.
        2. In the next window, double-click each package name on the left to accept the license agreement for each.
        3. Click Install.

        The download progress is shown at the bottom of the SDK Manager window. Do not exit the SDK Manager or it will cancel the download.

        Build something!

        With the above packages now in your Android SDK, you’re ready to build apps for Android. As new tools and other APIs become available, simply launch the SDK Manager to download the new packages for your SDK.

        Here are a few options for how you should proceed:

        Get started

        If you’re new to Android development, learn the basics of Android apps by following the guide to Building Your First App.

        Build for wearables

        If you’re ready to start building apps for Android wearables, see the guide to Building Apps for Android Wear.

        Use Google APIs

        To start using Google APIs, such as Maps or Play Game services, see the guide to Setting Up Google Play Services.

        Источник

        Signing Your Applications

        In this document

        See also

        Android requires that all apps be digitally signed with a certificate before they can be installed. Android uses this certificate to identify the author of an app, and the certificate does not need to be signed by a certificate authority. Android apps often use self-signed certificates. The app developer holds the certificate’s private key.

        Signing Overview

        You can sign an app in debug or release mode. You sign your app in debug mode during development and in release mode when you are ready to distribute your app. The Android SDK generates a certificate to sign apps in debug mode. To sign apps in release mode, you need to generate your own certificate.

        Signing in Debug Mode

        In debug mode, you sign your app with a debug certificate generated by the Android SDK tools. This certificate has a private key with a known password, so you can run and debug your app without typing the password every time you make a change to your project.

        Android Studio signs your app in debug mode automatically when you run or debug your project from the IDE.

        You can run and debug an app signed in debug mode on the emulator and on devices connected to your development manchine through USB, but you cannot distribute an app signed in debug mode.

        By default, the debug configuration uses a debug keystore, with a known password and a default key with a known password. The debug keystore is located in $HOME/.android/debug.keystore, and is created if not present. The debug build type is set to use this debug SigningConfig automatically.

        For more information about how to build and run apps in debug mode, see Building and Running.

        Signing in Release Mode

        In release mode, you sign your app with your own certificate:

        1. Create a keystore. A keystore is a binary file that contains a set of private keys. You must keep your keystore in a safe and secure place.
        2. Create a private key. A private key represents the entity to be identified with the app, such as a person or a company.

        Add the signing configuration to the build file for the app module:

      2. Invoke the assembleRelease build task from Android Studio.

      The package in app/build/apk/app-release.apk is now signed with your release key.

      Note: Including the passwords for your release key and keystore inside the build file is not a good security practice. Alternatively, you can configure the build file to obtain these passwords from environment variables or have the build process prompt you for these passwords.

      To obtain these passwords from environment variables:

      To have the build process prompt you for these passwords if you are invoking the build from the command line:

      After you complete this process, you can distribute your app and publish it on Google Play.

      Warning: Keep your keystore and private key in a safe and secure place, and ensure that you have secure backups of them. If you publish an app to Google Play and then lose the key with which you signed your app, you will not be able to publish any updates to your app, since you must always sign all versions of your app with the same key.

      The rest of this document provides detailed instructions about how to generate a private key and sign your apps in release mode with Android Studio.

      Signing Android Wear Apps

      When publishing Android Wear apps, you package the wearable app inside of a handheld app, because users cannot browse and install apps directly on the wearable. Both apps must be signed. For more information on packaging and signing Android Wear apps, see Packaging Wearable Apps.

      Signing Your App in Android Studio

      To sign your app in release mode in Android Studio, follow these steps:

        On the menu bar, click Build >Generate Signed APK.

      On the Generate Signed APK Wizard window, click Create new to create a new keystore.

      If you already have a keystore, go to step 4.

      On the New Key Store window, provide the required information as shown in figure 1.

      Your key should be valid for at least 25 years, so you can sign app updates with the same key through the lifespan of your app.

      Figure 1. Create a new keystore in Android Studio.

      On the Generate Signed APK Wizard window, select a keystore, a private key, and enter the passwords for both. Then click Next.

      Figure 2. Select a private key in Android Studio.

      On the next window, select a destination for the signed APK and click Finish.

      Figure 3. Generate a signed APK in Android Studio.

      Automatically Signing Your App

      In Android Studio, you can configure your project to sign your release APK automatically during the build process:

      1. On the project browser, right click on your app and select Open Module Settings.
      2. On the Project Structure window, select your app’s module under Modules.
      3. Click on the Signing tab.

      Select your keystore file, enter a name for this signing configuration (as you may create more than one), and enter the required information.

      Figure 4. Create a signing configuration in Android Studio.

      Under Signing Config, select the signing configuration you just created.

      Figure 5. Select a signing configuration in Android Studio.

      You can also specify your signing settings in Gradle configuration files. For more information, see Configuring Gradle Builds.

      Signing Considerations

      You should sign all of your apps with the same certificate throughout the expected lifespan of your applications. There are several reasons why you should do so:

      • App upgrade: When the system is installing an update to an app, it compares the certificate(s) in the new version with those in the existing version. The system allows the update if the certificates match. If you sign the new version with a different certificate, you must assign a different package name to the application—in this case, the user installs the new version as a completely new application.
      • App modularity: Android allows apps signed by the same certificate to run in the same process, if the applications so requests, so that the system treats them as a single application. In this way you can deploy your app in modules, and users can update each of the modules independently.
      • Code/data sharing through permissions: Android provides signature-based permissions enforcement, so that an app can expose functionality to another app that is signed with a specified certificate. By signing multiple apps with the same certificate and using signature-based permissions checks, your apps can share code and data in a secure manner.

      If you plan to support upgrades for an app, ensure that your key has a validity period that exceeds the expected lifespan of that app. A validity period of 25 years or more is recommended. When your key’s validity period expires, users will no longer be able to seamlessly upgrade to new versions of your application.

      If you plan to publish your apps on Google Play, the key you use to sign these apps must have a validity period ending after 22 October 2033. Google Play enforces this requirement to ensure that users can seamlessly upgrade apps when new versions are available.

      Securing Your Private Key

      Maintaining the security of your private key is of critical importance, both to you and to the user. If you allow someone to use your key, or if you leave your keystore and passwords in an unsecured location such that a third-party could find and use them, your authoring identity and the trust of the user are compromised.

      If a third party should manage to take your key without your knowledge or permission, that person could sign and distribute apps that maliciously replace your authentic apps or corrupt them. Such a person could also sign and distribute apps under your identity that attack other apps or the system itself, or corrupt or steal user data.

      Your private key is required for signing all future versions of your app. If you lose or misplace your key, you will not be able to publish updates to your existing appn. You cannot regenerate a previously generated key.

      Your reputation as a developer entity depends on your securing your private key properly, at all times, until the key is expired. Here are some tips for keeping your key secure:

      • Select strong passwords for the keystore and key.
      • Do not give or lend anyone your private key, and do not let unauthorized persons know your keystore and key passwords.
      • Keep the keystore file containing your private key in a safe, secure place.

      In general, if you follow common-sense precautions when generating, using, and storing your key, it will remain secure.

      Expiry of the Debug Certificate

      The self-signed certificate used to sign your application in debug mode has an expiration date of 365 days from its creation date. When the certificate expires, you will get a build error.

      To fix this problem, simply delete the debug.keystore file. The default storage location is in

      /.android/ on OS X and Linux, in C:\Documents and Settings\ \.android\ on Windows XP, and in C:\Users\ \.android\ on Windows Vista and Windows 7.

      The next time you build, the build tools will regenerate a new keystore and debug key.

      Note that, if your development machine is using a non-Gregorian locale, the build tools may erroneously generate an already-expired debug certificate, so that you get an error when trying to compile your application. For workaround information, see the troubleshooting topic I can’t compile my app because the build tools generated an expired debug certificate.

      Signing Your App Manually

      You do not need Android Studio to sign your app. You can sign your app from the command line using standard tools from the Android SDK and the JDK. To sign an app in release mode from the command line:

      Generate a private key using keytool . For example:

      This example prompts you for passwords for the keystore and key, and to provide the Distinguished Name fields for your key. It then generates the keystore as a file called my-release-key.keystore . The keystore contains a single key, valid for 10000 days. The alias is a name that you will use later when signing your app.

      Compile your app in release mode to obtain an unsigned APK.

      Sign your app with your private key using jarsigner :

      This example prompts you for passwords for the keystore and key. It then modifies the APK in-place to sign it. Note that you can sign an APK multiple times with different keys.

      Verify that your APK is signed. For example:

      Align the final APK package using zipalign .

      zipalign ensures that all uncompressed data starts with a particular byte alignment relative to the start of the file, which reduces the amount of RAM consumed by an app.

      Источник

      Читайте также:  Как отменить подписку апл с андроида
    Оцените статью