Can't create Distribute Certificate

Hello everyone!

I’ve designed a watch face for my Samsung Galaxy Classic S3 with Galaxy Watch Studio, but I’m having trouble running it on my device because I can’t get a Distribute Certificate. I got up to here:

After entering my account credentials I get this:

Any idea what it could be?

Other details:

  • I am able to get an Author Certificate
  • I have have tried connecting my watch via WiFi and SDB over BlueTooth

Did you scroll down and enter the captcha it isn’t obvious you have to do that after you enter your name and password.

Are you running Windows 7, if so you need to update Internet Explorer to the 64 bit version that installs a .DLL that the store needs.

Those are the two most common. Wait a day it seems to happen because of a cache too.

Samsung Developer Team

There is no captcha at the bottom of that:

Are we always supposed to have one?


  • I’m on Windows 10
  • I’m not sure what’s being cached, but I first got the error message a week ago

I apologize I don’t see the captcha either it must have changed. I was able to sign in and generate a new distributor certificate in the USA.

If you go to the C:\Program Files\Galaxy Watch Studio\ folder there is a file eclipsec click on it and it will create a log file of GWS. Run that and try to generate the Distributor certificate. If it fails to create a Distributor Certificate again close GWS. It will save the log in the users\username\Galaxywatchdesigner\ folder as watchface.log. Just maybe you can see something that helps probably not as I think this is a store connection issue.

Can you log into the seller portal successfully maybe you can open a 1:1 Enquiry there.

Samsung Developer Team

Interesting… I looked through the log and found this:

INFO [03/27-08:38:49,073]( - api_server_url =
INFO [03/27-08:38:49,074]( - auth_server_url =
DEBUG [03/27-08:38:49,084]( - Start to generate CSR for Tizen keystore...OK
DEBUG [03/27-08:38:49,085]( - generate keygen object...OK
DEBUG [03/27-08:38:49,259]( - generate keypair object...OK
DEBUG [03/27-08:38:49,260]( - generate PBE parameter set...OK
DEBUG [03/27-08:38:49,264]( - generate PKCS#8 encrypted key...OK
DEBUG [03/27-08:38:49,268]( - X509Principal param : CN=GearWatchDesigner, OU=, O=, L=, ST=, C=,
DEBUG [03/27-08:38:49,273]( - String index out of range: -1
INFO [03/27-08:38:49,273]( - Distributor CSR generation failed
ERROR [03/27-08:38:49,274]( - java.lang.Exception: java.lang.StringIndexOutOfBoundsException: String index out of range: -1
	at org.eclipse.swt.widgets.Display.runTimer(
	at org.eclipse.swt.widgets.Display.messageProc(
	at org.eclipse.swt.internal.win32.OS.DispatchMessageW(Native Method)
	at org.eclipse.swt.internal.win32.OS.DispatchMessage(
	at org.eclipse.swt.widgets.Display.readAndDispatch(
	at org.eclipse.swt.widgets.TypedListener.handleEvent(
	at org.eclipse.swt.widgets.EventTable.sendEvent(
	at org.eclipse.swt.widgets.Display.sendEvent(
	at org.eclipse.swt.widgets.Widget.sendEvent(
	at org.eclipse.swt.widgets.Display.runDeferredEvents(
	at org.eclipse.swt.widgets.Display.readAndDispatch(
	at org.eclipse.core.runtime.internal.adaptor.EclipseAppLauncher.runApplication(
	at org.eclipse.core.runtime.internal.adaptor.EclipseAppLauncher.start(
	at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
	at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
	at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
	at java.lang.reflect.Method.invoke(Unknown Source)
	at org.eclipse.equinox.launcher.Main.invokeFramework(
	at org.eclipse.equinox.launcher.Main.basicRun(
Caused by: java.lang.StringIndexOutOfBoundsException: String index out of range: -1
	at java.lang.String.substring(Unknown Source)
	at org.bouncycastle.asn1.x509.X509Name.<init>(Unknown Source)
	at org.bouncycastle.asn1.x509.X509Name.<init>(Unknown Source)
	at org.bouncycastle.asn1.x509.X509Name.<init>(Unknown Source)
	at org.bouncycastle.jce.X509Principal.<init>(Unknown Source)
	... 34 more

You can not have a + in your user name someone else reported this earlier this month. That is the issue.

Samsung Developer Program

That’s a shame. Will that be addressed in a future update or is it not even that high in the priority list?

It may help boost the priority if you open a bug report too.

scroll to the bottom and request developer support not store report.

Samsung Developer Team

Hi everyone,

I do have the same issues to create a Distribute Certificate :frowning: I did it once, and I therefore I have a file in the keystore folder (distributer.p12) as well as an author.p12 file

If I want to generate a CSR I’m able to choose the author.p12 file which I generated yesterday already. Why I’m not able to browse my Disk and choose the distributer.p12 file from yesterday?

So I alway need to generate a “new” distributer file. But if I start doing it, there is allways the request to connect the device or to enter the devise id…

Why is there no upload function for the existing distributor file???

Btw. today it is the same file I was working at like yesterday…

My system: W10, Garmin Watch 3 frontier, GWS V2.0.0_beta

Greetings, RookieJ :cowboy_hat_face:

You only need to generate a Distributor Certificate one time for your watch (unless it is updated to a new version, paired to a new watch or something else that causes a reset).

The Author Certificates tells Samsung who you are so it needs to be the same one for any uploaded apps/watch faces so keep it safe and duplicated if you plan to distribute anything on the store.

The Distributor Certificate basically tells the watch that the computer you are sending the app from is safe. the Distributor.p12 can have multiple certificates.

Are you sure it is asking for a Distributor File and not the RSA Encryption Key (which unlocks the encoded binary file).

Samsung Developer Relations

Good Morning Ron,

thanx for your answer :+1:

Did I get you right: Generating a Distributor and Author Certificate (GWS > Project > Author & Distribute Certificate only once, unless … [like you mentioned]) not just per project. As long as I have the same watch and the same GWS (same version) I don’t need to generate both files new?!

But now I have another issue: I’ve built my project and wanna run it on my GearWatch3, I push the RoD (F9) button, then scan devices … result=notice box “No Device Found…”

  • watch and PC belong to the same subnet
  • Debugging is “on” (watch)
  • WiFi is “on” (watch and PC)
    I’ve checked all 6 points in the Notice-Box …

What else can I do???

You only need to generate the Author Certificate once in a lifetime. Technically they do expire but they don’t enforce it for watch designers. You can renew it if it does expire. Distributor certificates have to be for every watch but it is the same .p12 file.

This is because at some time you tried to run on device and did not accept the RSA Encryption key. Your device is found, you know that because you generated a distributor certificate.

the binary is encoded and the RSA Encryption key is installed on the device so it can decode it. The first time you try to run on device it has a very brief period to accept it after that it blocks it.

In the C:\users\USERNAME\ folder is a hidden folder called .tizen in it are and sdb files. Rename them and restart everything computer and watch (Hold down the power key for about 15 seconds until it says restarting).

Give it a full minute to fully connect watch Wifi even though it says it is connected it may not be fully connected.

Put your watch on a factory installed watch face keep the watch active and keep looking at it.

launch GWS run on device and make sure you have the IP address selected in the connection window

Watch your watch and when the RSA Encryption key pops up select accept checkmark

You only have to accept the RSA Encryption key once per watch unless there is a system update. the minor ones don’t usually require a new Distributor certificate or RSA key

Samsung Developer Relations