| Profile type | Installs on | Watch out for |
|---|---|---|
| Development | Only devices whose UDID is in the profile | Your device must be added to the profile |
| Ad Hoc | Only devices whose UDID is in the profile | Your device must be added to the profile |
| Enterprise (in-house) | Any device | Shared enterprise certificates are revoked often |
| App Store | Cannot install apps directly | Use a Development, Ad Hoc or Enterprise profile instead |
Import into iClone or ESign
iClone is built on ESign, so the steps are the same in both apps.
- Save the .p12 file and the matching .mobileprovision file in the same folder. The app looks for the profile next to the certificate.
- Import both files into the app’s file list, either from the Files app or with the share sheet.
- Tap the .p12 file and choose to import it into the certificate library.
- Enter the certificate password.
- Open certificate management and check that the certificate shows as valid, together with its expiry date.
Import into KSign
Open the certificates section in KSign, add a new certificate, select the .p12 file and the .mobileprovision file, and enter the password. Exact labels can change between KSign versions. KSign 1.5.1 and later no longer accept the .ksign format, so import the original files.
Install iClone with your certificate in one step
If iClone is not installed yet, use online installation. Upload your .p12, password and .mobileprovision. The service checks the certificate with Apple before signing, then gives you an install button. The installed iClone already contains your certificate. Uploaded files are deleted after signing, and the signed app is deleted after 30 minutes.
Common import errors
- Wrong password: the .p12 password is set by whoever exported the certificate. Ask your certificate provider for it.
- No matching profile found: the .mobileprovision must belong to the same certificate and be in the same folder as the .p12.
- Device not included: Development and Ad Hoc profiles only install on listed devices. You can copy your UDID from iClone’s settings and send it to your provider.
- Expired or revoked: the certificate can no longer sign apps. See what to do when a certificate is revoked.
- App Store profile: these profiles cannot install apps outside the App Store.
A note on free certificates
Free certificates found online are usually shared enterprise certificates used by many people. Apple revokes them often, and apps may stop opening without warning. A certificate issued for your own device is more reliable. iClone’s partner iOSclone.com offers device certificates.
Get iClone
Download the IPA, or install iClone online with your own certificate. The certificate is imported into iClone automatically.
Frequently asked questions
Can I use the same certificate in ESign, KSign and iClone?
Yes. A certificate is not tied to one signing app. Import the same .p12 and .mobileprovision into each app.
Where do I find my iPhone’s UDID?
iClone and ESign can read the device UDID in their settings, and you can copy it from there.
Why does the app say the certificate does not include this device?
The profile is a Development or Ad Hoc profile that does not list your UDID. Apps signed with it cannot be installed on this iPhone. Ask your provider to add the device or use a profile that includes it.
Does iclone.download keep my certificate?
No. Uploaded certificates, passwords and profiles are used only for the current signing job and are deleted afterwards. The signed app is deleted after 30 minutes.