Test Azure Trusted Signing

This commit is contained in:
Michael Grafnetter
2024-10-06 19:59:12 +02:00
parent c418235c7f
commit 1faed78ade
+59 -64
View File
@@ -89,21 +89,6 @@ jobs:
shell: PowerShell
run: .\Build-PowerShellModule.ps1 -Configuration Release
- name: Cache DotNet Global Tools
id: cache-dotnet-globaltools
uses: actions/cache@v4
if: ${{ inputs.certificate_sign }}
with:
path: ~/.dotnet/tools
# Heuristics: The current list of required global tools is defined in this workflow file.
key: ${{ runner.os }}-DotNET-GlobalTools-Release-${{ hashFiles('.github/workflows/release.yml') }}
- name: Install Azure KeyVault Code Signing Tools
if: ${{ inputs.certificate_sign && steps.cache-dotnet-globaltools.outputs.cache-hit != 'true' }}
run: |
dotnet tool install --global AzureSignTool
dotnet tool install --global NuGetKeyVaultSignTool
- name: Azure Login
uses: azure/login@v2
if: ${{ inputs.certificate_sign }}
@@ -112,39 +97,50 @@ jobs:
tenant-id: ${{ secrets.SIGNING_TENANT_ID }}
allow-no-subscriptions: true
- name: Sign Binaries and Scripts
- name: Sign Scripts and Binaries
uses: azure/trusted-signing-action@v0.4.0
if: ${{ inputs.certificate_sign }}
with:
exclude-azure-cli-credential: false
exclude-environment-credential: true
exclude-workload-identity-credential: true
exclude-managed-identity-credential: true
exclude-shared-token-cache-credential: true
exclude-visual-studio-credential: true
exclude-visual-studio-code-credential: true
exclude-azure-powershell-credential: true
exclude-azure-developer-cli-credential: true
exclude-interactive-browser-credential: true
endpoint: https://weu.codesigning.azure.net/
trusted-signing-account-name: dsinternals-signing
certificate-profile-name: DSInternals
files: |
${{ github.workspace }}/Build/bin/PSModule/Release/DSInternals.Passkeys/DSInternals.Passkeys.psd1 ^
${{ github.workspace }}/Build/bin/PSModule/Release/DSInternals.Passkeys/DSInternals.Passkeys.psm1 ^
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn/release_net472/DSInternals.Win32.WebAuthn.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn/release_net48/DSInternals.Win32.WebAuthn.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn/release_netcoreapp3.1/DSInternals.Win32.WebAuthn.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn/release_net5.0/DSInternals.Win32.WebAuthn.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn/release_net6.0/DSInternals.Win32.WebAuthn.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn/release_net7.0/DSInternals.Win32.WebAuthn.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn/release_net8.0/DSInternals.Win32.WebAuthn.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn.Adapter/release_net472/DSInternals.Win32.WebAuthn.Adapter.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn.Adapter/release_net48/DSInternals.Win32.WebAuthn.Adapter.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn.Adapter/release_netcoreapp3.1/DSInternals.Win32.WebAuthn.Adapter.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn.Adapter/release_net5.0/DSInternals.Win32.WebAuthn.Adapter.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn.Adapter/release_net6.0/DSInternals.Win32.WebAuthn.Adapter.dll
${{ github.workspace }}/Build/bin/DSInternals.Win32.WebAuthn.Adapter/release_net7.0/DSInternals.Win32.WebAuthn.Adapter.dll
${{ github.workspace }}/Build/bin/Fido2UI/release/Fido2UI.exe
file-digest: SHA256
timestamp-rfc3161: http://timestamp.acs.microsoft.com
timestamp-digest: SHA256
- name: Copy Signed Binaries to PowerShell Module
shell: cmd
env:
SIGNING_VAULT_URL: ${{ secrets.SIGNING_VAULT_URL }}
SIGNING_CERTIFICATE_NAME: ${{ secrets.SIGNING_CERTIFICATE_NAME }}
if: ${{ inputs.certificate_sign }}
working-directory: Build/bin
timeout-minutes: 1
run: |
for /f %%i in ('az account get-access-token --resource "https://vault.azure.net" --query accessToken --output tsv') do set KEYVAULT_TOKEN=%%i
AzureSignTool sign ^
DSInternals.Win32.WebAuthn/release_net472/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net48/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_netcoreapp3.1/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net5.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net6.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net7.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net8.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net472/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net48/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_netcoreapp3.1/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net5.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net6.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net7.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
Fido2UI/release/Fido2UI.exe ^
PSModule/Release/DSInternals.Passkeys/DSInternals.Passkeys.psd1 ^
PSModule/Release/DSInternals.Passkeys/DSInternals.Passkeys.psm1 ^
--file-digest sha256 ^
--timestamp-digest sha256 ^
--timestamp-rfc3161 http://timestamp.digicert.com ^
--azure-key-vault-url "%SIGNING_VAULT_URL%" ^
--azure-key-vault-accesstoken "%KEYVAULT_TOKEN%" ^
--azure-key-vault-certificate "%SIGNING_CERTIFICATE_NAME%"
xcopy "DSInternals.Win32.WebAuthn/release_net48/DSInternals.Win32.WebAuthn.dll" "Fido2UI/release/" /Y /I /F
xcopy "DSInternals.Win32.WebAuthn/release_net48/DSInternals.Win32.WebAuthn.dll" "PSModule/Release/DSInternals.Passkeys/net48/" /Y /I /F
xcopy "DSInternals.Win32.WebAuthn/release_net6.0/DSInternals.Win32.WebAuthn.dll" "PSModule/Release/DSInternals.Passkeys/net6.0/" /Y /I /F
@@ -166,28 +162,27 @@ jobs:
run: dotnet pack --configuration Release --no-build
- name: Sign NuGet Packages
uses: azure/trusted-signing-action@v0.4.0
if: ${{ inputs.certificate_sign }}
shell: cmd
env:
SIGNING_VAULT_URL: ${{ secrets.SIGNING_VAULT_URL }}
SIGNING_CERTIFICATE_NAME: ${{ secrets.SIGNING_CERTIFICATE_NAME }}
working-directory: Build/package/release
run: |
for /f %%i in ('az account get-access-token --resource "https://vault.azure.net" --query accessToken --output tsv') do set KEYVAULT_TOKEN=%%i
NuGetKeyVaultSignTool sign *.nupkg ^
--file-digest sha256 ^
--timestamp-digest sha256 ^
--timestamp-rfc3161 http://timestamp.digicert.com ^
--azure-key-vault-url "%SIGNING_VAULT_URL%" ^
--azure-key-vault-accesstoken "%KEYVAULT_TOKEN%" ^
--azure-key-vault-certificate "%SIGNING_CERTIFICATE_NAME%"
NuGetKeyVaultSignTool sign *.snupkg ^
--file-digest sha256 ^
--timestamp-digest sha256 ^
--timestamp-rfc3161 http://timestamp.digicert.com ^
--azure-key-vault-url "%SIGNING_VAULT_URL%" ^
--azure-key-vault-accesstoken "%KEYVAULT_TOKEN%" ^
--azure-key-vault-certificate "%SIGNING_CERTIFICATE_NAME%"
with:
exclude-azure-cli-credential: false
exclude-environment-credential: true
exclude-workload-identity-credential: true
exclude-managed-identity-credential: true
exclude-shared-token-cache-credential: true
exclude-visual-studio-credential: true
exclude-visual-studio-code-credential: true
exclude-azure-powershell-credential: true
exclude-azure-developer-cli-credential: true
exclude-interactive-browser-credential: true
endpoint: https://weu.codesigning.azure.net/
trusted-signing-account-name: dsinternals-signing
certificate-profile-name: DSInternals
files-folder: ${{ github.workspace }}/Build/package/release
files-folder-filter: nupkg,snupkg
file-digest: SHA256
timestamp-rfc3161: http://timestamp.acs.microsoft.com
timestamp-digest: SHA256
- name: Upload NuGet Packages as Artifacts
uses: actions/upload-artifact@v4