packages icon indicating copy to clipboard operation
packages copied to clipboard

Unable to Find Signing Certificate on Big Sur

Open MattSenter opened this issue 4 years ago • 14 comments

I have set a signing certificate for my distribution project. It locates it just fine and shows the seal:

Screen Shot 2021-07-10 at 8 56 27 AM

However, when I run the build, it gives me an "Unable To Find Signing Certificate" error:

Screen Shot 2021-07-10 at 8 55 51 AM

I saw a couple of issues were related to full disk access permissions on Big Sur, so I enabled that, and still no luck. Any ideas?

MattSenter avatar Jul 10 '21 12:07 MattSenter

I should also mention after a build without the cert attached, I can manually sign the package with the cert in question from the command line:

productsign --sign "MY CERT" unsigned.pkg signed.pkg

MattSenter avatar Jul 10 '21 13:07 MattSenter

Is your certificate located in the Keychain of the user account you use to launch the build?

packagesdev avatar Jul 16 '21 22:07 packagesdev

I have the same problem, and yes, the certificate is in my keychain. Interesting thing is that the manual call triggered asking for the certficate (with the password), but not Packages.

mbrucher avatar Dec 07 '21 21:12 mbrucher

If, in Keychain Access.app, you select the private key of your Developer ID Installer certificate and, control-click it, choose Get Info and click the Access Control tab, what does it say?

packagesdev avatar Dec 07 '21 22:12 packagesdev

I don't have tabs, just a list with a bunch of info, none relating to access control (I'm on Big Sur 11.6)

mbrucher avatar Dec 07 '21 22:12 mbrucher

@mbrucher:

image

below you should see something that says "Developer ID Installer: Your Team Name (<Your team's identifier>)"

does that entry have a disclosure triangle on the left? clicking that should reveal the private key @packagesdev is referencing.

rudyrichter avatar Dec 07 '21 22:12 rudyrichter

I only have it in Certificates, not in My Certificates.

mbrucher avatar Dec 08 '21 07:12 mbrucher

I see the same issue with the latest Packages on macOS Monterey and an installer certificate (which is fully setup for all apps as above). I have to self sign after as @MattSenter said

andypoly avatar Jan 24 '22 15:01 andypoly

If you can provide detailed instructions on how the certificate was added to the keychain, I can try to reproduce the issue on Monterey. I had no luck trying to reproduce the latest reported issues with certificates.

packagesdev avatar Jan 25 '22 23:01 packagesdev

Hi, I am having the same exact issue running Packages 1.2.10 on Big Sur 11.6.1 The certificate was added to the keychain using "import items", it shows up in the "certificates" as well as "my certificates" tabs. It has a private key. I also added full disk permission to packages. So far nothing is working, any update on this issue?

chadesbois avatar May 24 '22 09:05 chadesbois

I was having the same issue, getting the "Unable To Find Signing Certificate" error, and finally found a fix.

This is on macOS Monterey 12.5.1, having Packages sign my installer with a Developer ID Installer certificate. In Keychain Access, that cert (and my other Apple certs, downloaded from their developer portal, and imported to Keychain Access via drag and drop) was showing up in the "Certificates" tab, not the "My Certificates" tab.

So here's the fix: double-click on the Developer ID Installer certificate in Keychain Access. At the top of the window, click on the Trust header to expand that section. It'll look like this:

Screen Shot 2022-10-14 at 11 53 13 PM

What you see in that screenshot was the defaults it came up with. For Code Signing and Time Stamping, I changed those to "Always Trust". After closing that window, I tried building the installer again with Packages, and this time it worked.

Weirdly, I went back later and switched those Trust settings back to their defaults, and Packages was still able to successfully build and sign the installer.

leighmarble avatar Oct 15 '22 06:10 leighmarble

Tried that, not working on Ventura (13.5)

Mcrich23 avatar Aug 24 '23 07:08 Mcrich23

I had much the same problems, but once I moved my certificates into the "login" section (I had them in the "system" section), all started working.

tonyvsuk avatar Nov 01 '23 14:11 tonyvsuk

on macOS 13.2, I need to set the keychain path(--keychain) to "/Library/Keychains/System.keychain" which my certificate located.

Samson721223 avatar Nov 20 '23 02:11 Samson721223