0

Our company is going to develop InHouse apps signed with Enterprise certificate. The question is: how can we protect the certificate from being stolen/shared by our developers but at the same time let the developers use it to sign our app?

Daniil
  • 1

1 Answers1

0

Trust your developers.

Or develop a workflow to send the unsigned app to some in-house authority that signs it and sends it back to the developers.

Or develop an in-house signing service that does the above automatically.

pipacs
  • 1,049
  • 11
  • 25
  • Thanks! But maybe can you share some companies/services for the options 2 and 3? – Daniil Apr 27 '21 at 14:43
  • A friend of mine worked for a company where local IT implemented 2. 3 is just my idea, I’m not aware of any public services implementing it. – pipacs Apr 28 '21 at 16:17