Google Play部署与上传密钥:Cordova应用签名使用咨询
Understanding deployment_cert.der and upload_cert.der for Google Play App Signing
Hey there! Let me break down exactly what these two certificates do and how they fit into your Cordova app's signing workflow:
1. upload_cert.der (Upload Certificate)
- This is the certificate you’ll use for all future release builds before uploading to Google Play.
- When you first set up Google Play App Signing with your original keystore (via the
cordova run android --releasecommand), Google generated this upload certificate as a trusted "gatekeeper." Only builds signed with this certificate will be accepted by Google Play for upload. - To use it with your Cordova builds, you’ll need to convert the .der file to a keystore format (like .jks) first. Run this
keytoolcommand:
After that, update your Cordova build commands or config to sign releases with this new upload keystore instead of your original one. For example:keytool -importcert -file upload_cert.der -keystore upload_keystore.jks -alias upload-keycordova run android --release --keystore=upload_keystore.jks --storePassword=your-store-pass --alias=upload-key --password=your-key-pass
2. deployment_cert.der (Deployment Certificate)
- This is the certificate Google uses to sign the final APKs/AABs that get delivered to users’ devices.
- You don’t need to use this file directly in your build process — Google handles re-signing your uploaded builds with this certificate automatically before publishing.
- Keep this certificate (and its hash) safe: it’s the one that matters for verifying app authenticity with third-party services, or if you ever need to transfer app ownership.
Quick Workflow Recap
- Sign your Cordova release builds with the upload keystore (converted from
upload_cert.der). - Upload the signed build to Google Play — Google validates it against your upload certificate.
- Google re-signs the build with the deployment certificate and delivers it to users.
- Backup both .der files and your keystores! Losing the upload certificate means you’ll have to request a reset from Google Play support, which is a time-consuming process.
内容的提问来源于stack exchange,提问作者Coatl
相关产品推荐
相关产品推荐

