jarsigner -digestalg SHA1 -sigalg MD5withRSA -tsa https://timestamp.geotrust.com/tsa -verbose -keystore "xxx.keystore" -storepass "storepass" -signedjar "signedjar" "unsignedjar" "keyAlias"
jarsigner -verify -verbose:all -certs Baidu_Claim_signed.apk
keytool -printcert -file XXX.RSA