mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Use authenticode cert for msix signing (#13330)
This commit is contained in:
@@ -3254,7 +3254,7 @@ function New-MSIXPackage
|
||||
# Appx manifest needs to be in root of source path, but the embedded version needs to be updated
|
||||
# cp-459155 is 'CN=Microsoft Windows Store Publisher (Store EKU), O=Microsoft Corporation, L=Redmond, S=Washington, C=US'
|
||||
# authenticodeFormer is 'CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US'
|
||||
$releasePublisher = 'CN=Microsoft Windows Store Publisher (Store EKU), O=Microsoft Corporation, L=Redmond, S=Washington, C=US'
|
||||
$releasePublisher = 'CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US'
|
||||
|
||||
$appxManifest = Get-Content "$RepoRoot\assets\AppxManifest.xml" -Raw
|
||||
$appxManifest = $appxManifest.Replace('$VERSION$', $ProductVersion).Replace('$ARCH$', $Architecture).Replace('$PRODUCTNAME$', $productName).Replace('$DISPLAYNAME$', $displayName).Replace('$PUBLISHER$', $releasePublisher)
|
||||
|
||||
@@ -100,11 +100,11 @@ foreach ($file in $ThirdPartyFiles) {
|
||||
}
|
||||
|
||||
foreach ($file in $MsixFiles) {
|
||||
# 'CP-459155' signs for the store only
|
||||
# AuthenticodeFormer works only for sideloading
|
||||
# 'CP-459155' is supposed to work for the store
|
||||
# AuthenticodeFormer works for sideloading and via a workaround, through the store
|
||||
# ----------------------------------------------
|
||||
# update releasePublisher in packaging.psm1 when this is changed
|
||||
New-FileElement -File $file -SignType 'CP-459155' -XmlDoc $signingXml -Job $job
|
||||
New-FileElement -File $file -SignType 'AuthenticodeFormer' -XmlDoc $signingXml -Job $job
|
||||
}
|
||||
|
||||
$signingXml.Save($path)
|
||||
|
||||
Reference in New Issue
Block a user