What is an iOS signing certificate? P12, mobileprovision and UDID explained
A plain-English explanation of iOS signing certificates: what the .p12 and .mobileprovision files are, why Apple requires them, and how sideloading apps works.
iOS only runs apps that are cryptographically signed by a certificate Apple trusts. App Store apps are signed by Apple. Anything you install outside the App Store — emulators, modded apps, your own builds — must be signed by a developer certificate that lists your device. That's what an iOS signing certificate is.
The two files you receive
| File | What it is | Where it goes |
|---|---|---|
cert.p12 | The private key + certificate, protected by a password | Imported into your signing app (Feather, KSign, ESign…) |
cert.mobileprovision | The provisioning profile: lists allowed UDIDs, entitlements and the expiry date | Imported together with the .p12 |
password.txt | The password that unlocks the .p12 | Typed once when importing |
Why your UDID is inside the profile
A development provisioning profile contains a list of device UDIDs. iOS checks that the phone's own UDID is on that list before it lets the app launch. That's why you must supply your UDID at checkout, and why one certificate is tied to one device.
Signing vs. installing
- You take an IPA (the app package) and a signing app re-signs it with your certificate.
- The signed IPA is installed over-the-air (OTA) or via a computer.
- On first launch, iOS verifies the signature against the profile. If the cert is valid and your UDID is listed, the app runs.
Developer vs. enterprise certificates
- Developer certificate (what lemoncert sells): tied to your UDID, requires trusting the developer once in Settings, very stable because Apple has little reason to revoke a profile used by a handful of devices.
- Enterprise certificate: no UDID list, shared by thousands of users, which is exactly why Apple revokes them within days. Cheap sites that skip the UDID step are selling these.
What happens when a certificate is revoked?
Apps signed with it stop opening. Nothing is damaged — you re-sign the IPAs with a fresh certificate and they work again. See Certificate revoked? What to do. lemoncert re-issues for free inside the warranty window.
Ready to try? Get a certificate — instant delivery, pay in crypto.
Frequently asked
Do I need a jailbreak?
No. Signing certificates are the non-jailbreak way to install apps outside the App Store. They work on every iOS version.
Does the certificate give access to my Apple ID or data?
No. It only signs app binaries. It has no access to your Apple ID, iCloud or personal data.