Basics
What is a certificate (cert), and which one should you use?
Enterprise certificates, personal UDID certificates and your own developer account explained, why certificates get revoked, and tips for buying one.
On this page
An iPhone only runs apps that are signed with an Apple-issued certificate. App Store apps are signed by Apple. When you install an IPA from elsewhere, the app has to be re-signed with another certificate. Apps like KSign, ESign and GBox do this right on the iPhone.
Three common certificate types
| Shared enterprise | Personal UDID certificate | Your own developer account | |
|---|---|---|---|
| Cost | Free or very cheap | Paid yearly | US$99/year |
| Stability | Low, often revoked | Good | Best |
| Needs UDID | No | Yes | Yes |
| How to allow it | Trust the app | Developer Mode | Developer Mode |
- Shared enterprise: a certificate meant for one company’s internal apps, shared among thousands of people. “Enterprise” only means the certificate belongs to a company: individuals can still use it. Apple detects this and revokes it quickly, sometimes within days.
- Personal UDID certificate: the seller registers your device’s UDID in a developer account. Much more stable, but it can still be revoked if Apple bans that account.
- Your own developer account: join the Apple Developer Program for US$99/year and register up to 100 devices per device type per year. The most stable option, because you’re in control.
Your free Apple Account can also sign apps for your own device. That’s what SideStore uses: legitimate and free, but each signature only lasts 7 days.
What’s in a certificate set?
- A
.p12file: the signing key, protected by a password. - A
.mobileprovisionfile: the provisioning profile, which lists the devices the certificate works on. - The password for the
.p12.
Keep your set safe and don’t share it. The more people use a certificate, the sooner it gets revoked.
What does “revoked” mean?
When Apple revokes a certificate, every app signed with it stops opening. The app crashes on launch, or iOS says it’s no longer available. The only fix is to re-sign the app with a valid certificate.
Tips for buying a certificate
- Ask whether it’s a personal UDID certificate or a shared one.
- Ask about the warranty: if it gets revoked early, will they reissue or refund?
- Check the expiry date right after importing it into KSign or ESign.
- Never give anyone your Apple Account password. Buying a certificate never requires it.
Found a mistake or an outdated step? Let us know so we can update it.