-
Notifications
You must be signed in to change notification settings - Fork 0
feat: firma de código para distribución interna #4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,63 @@ | ||
| <# | ||
| .SYNOPSIS | ||
| Crea un certificado de firma de código AUTO-FIRMADO para Margoth. | ||
|
|
||
| .DESCRIPTION | ||
| Uso interno: firmar Margoth para equipos que tú controlas. NO sirve para | ||
| quitar SmartScreen en distribución pública (eso requiere un certificado EV | ||
| comprado). El certificado queda en el almacén del usuario (Cert:\CurrentUser\My) | ||
| y se exportan dos archivos en la carpeta `signing/`: | ||
|
|
||
| - Margoth-CodeSigning.cer -> PÚBLICO. Se instala en los equipos destino | ||
| para "confiar" en la firma. | ||
| - Margoth-CodeSigning.pfx -> PRIVADO (con contraseña). Respáldalo; permite | ||
| firmar desde otro equipo. NO se sube al repo. | ||
|
|
||
| Correr una sola vez. Válido por 5 años. | ||
|
|
||
| .PARAMETER PfxPassword | ||
| Contraseña para proteger el .pfx exportado (respaldo de la clave privada). | ||
|
|
||
| .PARAMETER Publisher | ||
| Nombre del editor (CN del certificado). Debe coincidir con AppPublisher del | ||
| instalador para que la identidad sea consistente. | ||
| #> | ||
| param( | ||
| [Parameter(Mandatory = $true)] | ||
| [string]$PfxPassword, | ||
|
|
||
| [string]$Publisher = "Carlos G", | ||
|
|
||
| [int]$YearsValid = 5 | ||
| ) | ||
|
|
||
| $ErrorActionPreference = "Stop" | ||
|
|
||
| $root = Split-Path -Parent $PSScriptRoot | ||
| $outDir = Join-Path $root "signing" | ||
| New-Item -ItemType Directory -Force -Path $outDir | Out-Null | ||
|
|
||
| Write-Host "Creando certificado de firma de código para '$Publisher'..." | ||
| $cert = New-SelfSignedCertificate ` | ||
| -Type CodeSigningCert ` | ||
| -Subject "CN=$Publisher" ` | ||
| -FriendlyName "Margoth Code Signing" ` | ||
| -CertStoreLocation "Cert:\CurrentUser\My" ` | ||
| -KeyUsage DigitalSignature ` | ||
| -KeyExportPolicy Exportable ` | ||
| -NotAfter (Get-Date).AddYears($YearsValid) | ||
|
|
||
| Write-Host " Thumbprint: $($cert.Thumbprint)" | ||
|
|
||
| $cerPath = Join-Path $outDir "Margoth-CodeSigning.cer" | ||
| $pfxPath = Join-Path $outDir "Margoth-CodeSigning.pfx" | ||
|
|
||
| Export-Certificate -Cert $cert -FilePath $cerPath | Out-Null | ||
| $secure = ConvertTo-SecureString -String $PfxPassword -Force -AsPlainText | ||
| Export-PfxCertificate -Cert $cert -FilePath $pfxPath -Password $secure | Out-Null | ||
|
|
||
| Write-Host "" | ||
| Write-Host "Listo:" | ||
| Write-Host " Público (repartir a equipos): $cerPath" | ||
| Write-Host " Privado (respaldar, NO subir): $pfxPath" | ||
| Write-Host " Thumbprint para firmar: $($cert.Thumbprint)" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,45 @@ | ||
| <# | ||
| .SYNOPSIS | ||
| Instala el certificado público de Margoth como CONFIABLE en este equipo. | ||
|
|
||
| .DESCRIPTION | ||
| Correr UNA vez en cada equipo donde se vaya a instalar Margoth. Importa | ||
| `Margoth-CodeSigning.cer` a: | ||
| - Entidades de certificación raíz de confianza (valida la cadena) | ||
| - Editores de confianza (reconoce al editor) | ||
|
|
||
| Tras esto, la firma de Margoth.exe y de Margoth_Setup.exe aparece como | ||
| VÁLIDA y desaparece el aviso de "Editor desconocido". | ||
|
|
||
| NOTA: al importar a la raíz de confianza, Windows mostrará un cuadro de | ||
| seguridad pidiendo confirmación. Es normal: acepta para completar. | ||
|
|
||
| .PARAMETER CerPath | ||
| Ruta al archivo .cer público. Por defecto, junto a este script en signing\. | ||
|
|
||
| .PARAMETER AllUsers | ||
| Instala para TODOS los usuarios del equipo (requiere ejecutar como | ||
| administrador). Sin este switch, se instala solo para el usuario actual. | ||
| #> | ||
| param( | ||
| [string]$CerPath, | ||
| [switch]$AllUsers | ||
| ) | ||
|
|
||
| $ErrorActionPreference = "Stop" | ||
|
|
||
| if (-not $CerPath) { | ||
| $root = Split-Path -Parent $PSScriptRoot | ||
| $CerPath = Join-Path $root "signing\Margoth-CodeSigning.cer" | ||
| } | ||
| if (-not (Test-Path $CerPath)) { | ||
| throw "No se encontró el certificado: $CerPath" | ||
| } | ||
|
|
||
| $scope = if ($AllUsers) { "LocalMachine" } else { "CurrentUser" } | ||
| Write-Host "Instalando confianza del certificado ($scope) desde: $CerPath" | ||
|
|
||
| Import-Certificate -FilePath $CerPath -CertStoreLocation "Cert:\$scope\Root" | Out-Null | ||
| Import-Certificate -FilePath $CerPath -CertStoreLocation "Cert:\$scope\TrustedPublisher" | Out-Null | ||
|
|
||
| Write-Host "Listo. El certificado de Margoth ahora es de confianza en este equipo." | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,64 @@ | ||
| <# | ||
| .SYNOPSIS | ||
| Firma (Authenticode) el ejecutable de Margoth y/o el instalador. | ||
|
|
||
| .DESCRIPTION | ||
| Usa el certificado de firma de código del almacén del usuario | ||
| (Cert:\CurrentUser\My) sin necesidad de signtool ni de la contraseña del | ||
| .pfx. Agrega sello de tiempo RFC3161 para que la firma siga siendo válida | ||
| después de que el certificado expire. | ||
|
|
||
| Por defecto firma ambos artefactos si existen: | ||
| - dist\Margoth\Margoth.exe (la app) | ||
| - dist\Margoth_Setup.exe (el instalador) | ||
|
|
||
| Flujo recomendado de release: | ||
| 1. python build_exe.py # genera dist\Margoth\ | ||
| 2. tools\sign.ps1 -AppOnly # firma Margoth.exe | ||
| 3. ISCC margoth_installer.iss # empaqueta el .exe YA firmado | ||
| 4. tools\sign.ps1 -InstallerOnly # firma Margoth_Setup.exe | ||
|
|
||
| .PARAMETER Subject | ||
| CN del certificado a usar (por defecto "Carlos G"). | ||
|
|
||
| .PARAMETER TimestampServer | ||
| Servidor de sello de tiempo RFC3161. | ||
| #> | ||
| param( | ||
| [string]$Subject = "Carlos G", | ||
| [string]$TimestampServer = "http://timestamp.digicert.com", | ||
| [switch]$AppOnly, | ||
| [switch]$InstallerOnly | ||
| ) | ||
|
Owito marked this conversation as resolved.
|
||
|
|
||
| $ErrorActionPreference = "Stop" | ||
| $root = Split-Path -Parent $PSScriptRoot | ||
|
|
||
| $cert = Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert | | ||
| Where-Object { $_.Subject -eq "CN=$Subject" } | | ||
| Sort-Object NotAfter -Descending | | ||
| Select-Object -First 1 | ||
|
Owito marked this conversation as resolved.
|
||
|
|
||
| if (-not $cert) { | ||
| throw "No se encontró un certificado de firma con CN=$Subject. Corre primero tools\New-CodeSigningCert.ps1." | ||
| } | ||
| Write-Host "Firmando con: $($cert.Subject) [$($cert.Thumbprint)]" | ||
|
|
||
| $targets = @() | ||
| if (-not $InstallerOnly) { $targets += (Join-Path $root "dist\Margoth\Margoth.exe") } | ||
| if (-not $AppOnly) { $targets += (Join-Path $root "dist\Margoth_Setup.exe") } | ||
|
|
||
| foreach ($file in $targets) { | ||
| if (-not (Test-Path $file)) { | ||
| Write-Host " (omitido, no existe) $file" | ||
| continue | ||
| } | ||
| $res = Set-AuthenticodeSignature -FilePath $file -Certificate $cert ` | ||
| -TimestampServer $TimestampServer -HashAlgorithm SHA256 | ||
| Write-Host " $($res.Status) -> $file" | ||
| if ($res.Status -ne "Valid") { | ||
| throw "La firma de $file falló: $($res.StatusMessage)" | ||
| } | ||
| } | ||
|
|
||
| Write-Host "Firma completada." | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.