Fix exe signing with third party signing for WiX engine (#23878) (#23926)

This commit is contained in:
Aditya Patwardhan
2024-06-11 14:12:11 -07:00
committed by GitHub
parent 32ccc51106
commit 53ae33a52b
5 changed files with 31 additions and 3 deletions
+1
View File
@@ -136,6 +136,7 @@ jobs:
- name: DOTNET_SKIP_FIRST_TIME_EXPERIENCE
value: 1
- group: DotNetPrivateBuildAccess
- group: certificate_logical_to_actual
- name: ob_outputDirectory
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
- name: ob_sdl_codeSignValidation_enabled
+1
View File
@@ -81,6 +81,7 @@ jobs:
- name: NugetSecurityAnalysisWarningLevel
value: none
- group: DotNetPrivateBuildAccess
- group: certificate_logical_to_actual
- name: ob_outputDirectory
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
- name: ob_sdl_codeSignValidation_enabled
+1 -1
View File
@@ -128,7 +128,7 @@ steps:
displayName: Sign 3rd Party files
inputs:
command: 'sign'
signing_profile: 135020002
signing_profile: $(msft_3rd_party_cert_id)
files_to_sign: '**\*.dll;**\*.exe'
search_root: $(Pipeline.Workspace)/thirdPartyToBeSigned
@@ -17,6 +17,7 @@ jobs:
- name: DOTNET_SKIP_FIRST_TIME_EXPERIENCE
value: 1
- group: DotNetPrivateBuildAccess
- group: certificate_logical_to_actual
- name: ob_outputDirectory
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
- name: ob_sdl_codeSignValidation_enabled
+27 -2
View File
@@ -18,6 +18,7 @@ jobs:
- name: skipNugetSecurityAnalysis
value: true
- group: DotNetPrivateBuildAccess
- group: certificate_logical_to_actual
- name: ob_outputDirectory
value: '$(Build.ArtifactStagingDirectory)\ONEBRANCH_ARTIFACT'
- name: ob_sdl_binskim_enabled
@@ -199,11 +200,35 @@ jobs:
Set-Location $repoRoot
$exePath = New-ExePackage -ProductVersion $version -ProductTargetArchitecture $runtime -MsiLocationPath $msiLocation
Write-Verbose -Verbose "setting vso[task.setvariable variable=exePath]$exePath"
Write-Host "##vso[task.setvariable variable=exePath]$exePath"
Write-Verbose -Verbose "exePath: $exePath"
displayName: 'Make exe package'
$enginePath = Join-Path -Path '$(System.ArtifactsDirectory)\unsignedEngine' -ChildPath engine.exe
Expand-ExePackageEngine -ExePath $exePath -EnginePath $enginePath
displayName: 'Make exe and expand package'
- task: onebranch.pipeline.signing@1
displayName: Sign MSI packages
displayName: Sign exe engine
inputs:
command: 'sign'
signing_profile: $(msft_3rd_party_cert_id)
files_to_sign: '$(System.ArtifactsDirectory)\unsignedEngine\*.exe'
search_root: '$(Pipeline.Workspace)'
- pwsh: |
$repoRoot = "$env:REPOROOT"
Import-Module "$repoRoot\build.psm1"
Import-Module "$repoRoot\tools\packaging"
$exePath = '$(exePath)'
$enginePath = Join-Path -Path '$(System.ArtifactsDirectory)\unsignedEngine' -ChildPath engine.exe
$enginePath | Get-AuthenticodeSignature | out-string | Write-Verbose -verbose
Compress-ExePackageEngine -ExePath $exePath -EnginePath $enginePath
displayName: Compress signed exe package
- task: onebranch.pipeline.signing@1
displayName: Sign exe packages
inputs:
command: 'sign'
signing_profile: external_distribution