Manipulating Private Key Users

Either a single user is associated with a key in the keystore or it is accessible to all. A list is available of UIDs identifying applications that can use a key. Only these applications have access to the key, by default these are also the applications which can see the key. An application can programmatically list keys it cannot use by providing a suitable filter.

Only the key owner can modify the users associated with a given key. keytool provides a number of commands to manipulate the users of a given key. The following sections detail the users of the keys.