Move ESRP key codes into the certificate_logical_to_actual variable group

The `CP-…` key codes used for ESRP signing are now set from ADO via the
`certificate_logical_to_actual` variable group. The templates reference
the following variables instead of literal codes:

- `$(authenticode_cert_id)`
- `$(authenticode_test_cert_id)`
- `$(nuget_cert_id)`
- `$(apple_cert_id)`
- `$(pgp_linux_cert_id)`
- `$(pgp_release_cert_id)`

`nupkg.yml`, `mac-package-build.yml`, and `linux-package-build.yml` pick
up the new group import. `linux-package-build.yml` also now selects the
PGP signing profile based on whether `jobName` starts with `mariner`, so
`PowerShell-Packages-Stages.yml` no longer threads a `signingProfile`
parameter in for the two Mariner jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
Andy Jordan
2026-05-01 13:52:34 -07:00
co-authored by Copilot
parent 0990ddc642
commit 2237859aa8
7 changed files with 23 additions and 14 deletions
+11 -3
View File
@@ -3,7 +3,6 @@ parameters:
signedeDrop: 'drop_linux_sign_linux_x64'
packageType: deb
jobName: 'deb'
signingProfile: 'CP-450779-pgpdetached'
jobs:
- job: ${{ parameters.jobName }}
@@ -20,6 +19,7 @@ jobs:
- name: skipNugetSecurityAnalysis
value: true
- group: DotNetPrivateBuildAccess
- group: certificate_logical_to_actual
- name: ob_outputDirectory
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
- name: ob_sdl_binskim_enabled
@@ -34,8 +34,16 @@ jobs:
value: $(Build.SourcesDirectory)/PowerShell/.config/tsaoptions.json
- name: ob_sdl_credscan_suppressionsFile
value: $(Build.SourcesDirectory)/PowerShell/.config/suppress.json
- name: SigningProfile
value: ${{ parameters.signingProfile }}
# PGP signing profile selection: Mariner (Azure Linux) packages ship through
# a different distribution channel and must be signed with the Mariner release
# key; all other Linux packages use the standard PowerShell Linux key. Both
# key codes come from the `certificate_logical_to_actual` variable group.
- ${{ if startsWith(parameters.jobName, 'mariner') }}:
- name: SigningProfile
value: $(pgp_release_cert_id)
- ${{ else }}:
- name: SigningProfile
value: $(pgp_linux_cert_id)
steps:
- checkout: self
+4 -2
View File
@@ -22,6 +22,7 @@ jobs:
- name: skipNugetSecurityAnalysis
value: true
- group: DotNetPrivateBuildAccess
- group: certificate_logical_to_actual
- name: ob_outputDirectory
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
- name: ob_sdl_binskim_enabled
@@ -187,6 +188,7 @@ jobs:
type: windows
variables:
- group: certificate_logical_to_actual
- name: ob_outputDirectory
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
- name: ob_sdl_binskim_enabled
@@ -234,7 +236,7 @@ jobs:
inline_operation: |
[
{
"KeyCode": "CP-401337-Apple",
"KeyCode": "$(apple_cert_id)",
"OperationCode": "MacAppDeveloperSign",
"ToolName": "sign",
"ToolVersion": "1.0",
@@ -253,7 +255,7 @@ jobs:
inline_operation: |
[
{
"KeyCode": "CP-401337-Apple",
"KeyCode": "$(apple_cert_id)",
"OperationCode": "MacAppNotarize",
"ToolName": "sign",
"ToolVersion": "1.0",
+1 -1
View File
@@ -168,7 +168,7 @@ jobs:
inline_operation: |
[
{
"KeyCode": "CP-401337-Apple",
"KeyCode": "$(apple_cert_id)",
"OperationCode": "MacAppDeveloperSign",
"ToolName": "sign",
"ToolVersion": "1.0",
+3 -2
View File
@@ -23,6 +23,7 @@ jobs:
- group: mscodehub-feed-read-general
- group: mscodehub-feed-read-akv
- group: DotNetPrivateBuildAccess
- group: certificate_logical_to_actual
steps:
- checkout: self
@@ -208,7 +209,7 @@ jobs:
displayName: Sign nupkg files
inputs:
command: 'sign'
cp_code: 'CP-401405'
cp_code: '$(nuget_cert_id)'
files_to_sign: '**\*.nupkg'
search_root: '$(Pipeline.Workspace)\nupkg'
@@ -268,7 +269,7 @@ jobs:
displayName: Sign nupkg files
inputs:
command: 'sign'
cp_code: 'CP-401405'
cp_code: '$(nuget_cert_id)'
files_to_sign: '**\*.nupkg'
search_root: '$(Pipeline.Workspace)\globaltools'
+3 -3
View File
@@ -6,11 +6,11 @@ parameters:
steps:
- powershell: |
$shouldSign = $true
$authenticodeCert = 'CP-230012'
$msixCert = 'CP-230012'
$authenticodeCert = '$(authenticode_cert_id)'
$msixCert = '$(authenticode_cert_id)'
if($env:IS_DAILY -eq 'true')
{
$authenticodeCert = 'CP-460906'
$authenticodeCert = '$(authenticode_test_cert_id)'
}
if($env:SKIP_SIGNING -eq 'Yes')
{
@@ -93,7 +93,6 @@ stages:
signedDrop: 'drop_linux_sign_linux_fxd_x64_mariner'
packageType: rpm-fxdependent #mariner-x64
jobName: mariner_x64
signingProfile: 'CP-459159-pgpdetached'
- template: /.pipelines/templates/linux-package-build.yml@self
parameters:
@@ -101,7 +100,6 @@ stages:
signedDrop: 'drop_linux_sign_linux_fxd_arm64_mariner'
packageType: rpm-fxdependent-arm64 #mariner-arm64
jobName: mariner_arm64
signingProfile: 'CP-459159-pgpdetached'
- template: /.pipelines/templates/linux-package-build.yml@self
parameters:
@@ -315,7 +315,7 @@ jobs:
displayName: Sign nupkg files
inputs:
command: 'sign'
cp_code: 'CP-401405'
cp_code: '$(nuget_cert_id)'
files_to_sign: '**\*.nupkg'
search_root: '$(ob_outputDirectory)\globaltool'
condition: and(succeeded(), eq(variables['Architecture'], 'fxdependent'))