Files
Triple-C/scripts/windows-verify-signatures.ps1
T

45 lines
2.1 KiB
PowerShell
Raw Normal View History

# windows-verify-signatures.ps1 <path-or-wildcard>... - fail unless every file
# carries a valid, timestamped Authenticode signature.
#
# The check that makes signing load-bearing rather than hopeful: Tauri skips
# signing silently in some configurations (no sign command, --no-sign), and an
# unsigned installer looks exactly like a signed one until SmartScreen blocks
# it on a user's machine. Every pattern must match at least one file, so a
# bundle that was never produced cannot pass either.
param([Parameter(Mandatory = $true, ValueFromRemainingArguments = $true)][string[]]$Patterns)
$ErrorActionPreference = 'Stop'
if (-not $env:TRIPLE_C_SIGNTOOL) { throw 'TRIPLE_C_SIGNTOOL is not set - run windows-signing-setup.ps1 first' }
$files = foreach ($pattern in $Patterns) {
$found = @(Get-ChildItem -Path $pattern -File -ErrorAction SilentlyContinue)
if ($found.Count -eq 0) { throw "Nothing to verify matches $pattern" }
$found
}
$failed = @()
foreach ($file in $files) {
# signtool's own check: chain to a trusted root under the default
# Authenticode policy.
# Stop relaxed for the native call, as in windows-sign.ps1.
$ErrorActionPreference = 'Continue'
$verifyOutput = & $env:TRIPLE_C_SIGNTOOL verify /pa $file.FullName 2>&1 | ForEach-Object { "$_" }
$signtoolOk = ($LASTEXITCODE -eq 0)
$ErrorActionPreference = 'Stop'
if (-not $signtoolOk) { $verifyOutput | Write-Host }
# And the timestamp, which signtool verify does not require.
$sig = Get-AuthenticodeSignature -FilePath $file.FullName
$timestamped = $null -ne $sig.TimeStamperCertificate
if ($signtoolOk -and $sig.Status -eq 'Valid' -and $timestamped) {
Write-Host "OK $($file.Name) - $($sig.SignerCertificate.Subject)"
} else {
Write-Host "FAIL $($file.Name) - status $($sig.Status), signtool $(if ($signtoolOk) {'ok'} else {'failed'}), timestamped $timestamped"
$failed += $file.Name
}
}
if ($failed.Count -gt 0) { throw "Not validly signed: $($failed -join ', ')" }
Write-Host "All $(@($files).Count) files are signed and timestamped."