Hello, Atlassian Community,
As we communicated in October 2024, in 2025 we’re rolling out app signing to significantly improve the security of app installations. This feature is designed to verify the integrity and origin of application files using a digital signature. In this way, only trusted applications can be installed on an instance. App signing affects only new app installations, previously installed apps will not undergo verification.
When will app signing be available?
The change is being gradually rolled out across Atlassian Data Center (DC) products in their next releases. To activate app signing, you will need to upgrade to the following product versions:
-
Jira Software and Jira Service Management 10.5 to be released in Mar 2025
-
Confluence 9.4 to be released in Apr 2025
-
Bitbucket 9.6 to be released in Mar 2025
-
Bamboo 11.0 to be released in the first half of 2025
-
Crowd 6.3 to be released in Mar 2025
Is app signing currently required?
Currently, app signing is disabled by default. The grace period will last until the next major releases of Atlassian DC products in Q3 and Q4 of 2025, after which app signing will be enabled by default.
When app signing is enabled, admins are required to configure it correctly and set up their Trust store, otherwise, customers will not be able to install any application.
What changes for the customers?
As a customer, use the grace period to adapt your processes. The steps you need to take differ depending on whether you install applications from the Marketplace or build your custom applications. In either case, the first step is to set up a Trust store and enable app signing. You will have full control over the Trust store, therefore, you can revoke or remove untrusted certificates. UPM will list all trusted certificates and notify admins about nearly expired ones.
You can also install the app via the file system without using the app signing feature.
Install signed apps from Marketplace
-
Enable app signing. For details, see Configuring UPM app signature check.
-
Download and install Certificate Authority (CA) from Atlassian. For details, see Updating Atlassian Certificate Bundles.
-
Enjoy the safe app installations from Marketplace.
Install custom apps
If you use custom application builds, you can sign and secure your apps:
-
Enable app signing. For details, see Configuring UPM app signature check.
-
Create app signature and verification certificate as described in Generating app signature and verification certificate using OpenSSL.
-
Put your new certificate in your Trust store similarly to Updating Atlassian Certificate Bundles.
-
Install the signed application.
If you’re experiencing issues, check out app signing troubleshooting or leave us a comment here.
Thanks for being part of this journey!