Upload keys and application signing keys can serve different roles. Reflect that distinction in access management and recovery.
Evaluation approach
Document Play App Signing and your own responsibilities. Make each key's pipeline role visible.
Application example
The package submitted for protection and the package installed by users may have different certificate expectations.
Limits and considerations
Recovery or rotation of one key does not imply the same process applies to the other.
What should a recovery exercise cover?
Verify authorized access and required records as well as the written procedure. Treat upload-key loss and app-signing-key changes as distinct operations.
Checks and decisions
- Separate key roles
- Verify final certificates
- Document recovery
Sources
The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.