Mac OS X - Creating Key Certificates for Atlassian Bamboo

I have a Bamboo plan that creates a package, and I want to sign this package with my developer certificate. In my build script I have this:

productsign --sign "Name of my certificate" "input.pkg" "output.pkg" 

Running this script from the command line works as expected. However, running the script from Bamboo, I always get the error:

 productsign: error: Could not find appropriate signing identity for "Name of my certificate" 

I assume this should be due to the context in which the build script is run when starting from Bamboo. How to make the certificate suitable for use in Bamboo? It is installed in System , not login .

+7
installer code-signing macos bamboo
source share
3 answers

If you need to run Bamboo as root , you need to copy the corresponding certificates from the login to the System chain using Keychain Access (Applications> Utilities).

Having said that, it would be better to run Bamboo as a user instead of root . For example. if you need to use mobility profiles to sign any iOS builds on the same server, root will not work.

+2
source share

Have you tried sudo'ing operations?

i.e:.

 sudo productsign --sign "Name of my certificate" "input.pkg" "output.pkg" 

As the key is in the system keychain (which perhaps should not be for your use case?), You probably do not have access to it as a "regular" user, although [by design] you have access to the certificates in it .

+1
source share

My recommendation is to store the keys you need in a separate keychain. This will facilitate their search and management. Just create a new keychain and move your certificate to it; keep it somewhere convenient. Then I sign things this way (I use codesign , but --productsign is the same). I am not building as root, and I am not using sudo for this.

 # Keychain that holds all the required signing certificates # To create a keychain like this, create it in "Keychain Access" and copy all your certificates into it # Then set its timeout to infinite (so it doesn't re-lock itself during the build): # security set-keychain-settings <path> # Passing no "-t" option means "no timeout." # Generally you should just be able to copy this file from build host to build host as needed. Then # add it to the available keychains using Keychain Access, File>Add Keychain…. If you don't add it to # Keychain Access, you'll receive signing error CSSMERR_TP_NOT_TRUSTED, since it won't recognize the # entire chain keychain=~/Library/Keychains/MyProduct.keychain keychain_password=somepassword # If you have one on the keychain cert_identifier='My Signing Name' ... # We assume the keychain has an infinite timeout, so we just unlock it once here. if ! security unlock-keychain -p "${keychain_password}" ${keychain} ; then echo "Cannot unlock keychain. Cannot sign on this host." exit 1 fi sign() { name=$1 ; shift paths=$* if ${sign} ; then echo "** SIGNING $name **" chmod u+w $paths codesign --keychain ${keychain} -f -s ${cert_identifier} $paths fi } sign "The Whole Package" something.pkg 
0
source share

All Articles