Fix notarization after latest Apple changes (#23843)
Notarization from the fleetctl-docker image is broken actually: ``` fleetctl package --type=pkg --fleet-url=myurl --enroll-secret=mysecret --macos-devid-pem-content=XYZ --notarize --app-store-connect-api-key-id=XYZ --app-store-connect-api-key-issuer=XYZ --app-store-connect-api-key-content=XYZ [..] transporter error> Package Summary: transporter error> transporter error> 1 package(s) were not uploaded because they had problems: transporter error> /tmp/apple-codesign-QAsKT8/17081d03-fdc8-46cd-873a-2970f7be9c7c.itmsp - Error Messages: transporter error> Notarization of MacOS applications using altool has been decommissioned. Please use notarytool. See: https://developer.apple.com/documentation/technotes/tn3147-migrating-to-the-latest-notarization-tool (4200) transporter error> [2024-11-15 13:35:47 UTC] <main> DBG-X: Returning 1 Error: I/O error: command ["/usr/local/bin/iTMSTransporter", "-m", "upload", "-apiIssuer", "XYZ", "-apiKey", "XYZ", "-f", "/tmp/apple-codesign-QAsKT8/17081d03-fdc8-46cd-873a-2970f7be9c7c.itmsp", "-vp", "json"] exited with code 1 Error: rcodesign notarize: exit status 1 ``` Luckily, bumping `rcodesign` version is enough to make it work again. # Checklist for submitter - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements) - [ ] Added support on fleet's osquery simulator `cmd/osquery-perf` for new osquery data ingestion features. - [ ] Added/updated tests - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes - [ ] If database migrations are included, checked table schema to confirm autoupdate - For database migrations: - [ ] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [ ] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [ ] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). - [ ] Manual QA for all new/changed functionality - For Orbit and Fleet Desktop changes: - [ ] Orbit runs on macOS, Linux and Windows. Check if the orbit feature/bugfix should only apply to one platform (`runtime.GOOS`). - [ ] Manual QA must be performed in the three main OSs, macOS, Windows and Linux. - [ ] Auto-update manual QA, from released version of component to new version (see [tools/tuf/test](../tools/tuf/test/README.md)).
This commit is contained in:
@@ -2,7 +2,7 @@ FROM rust:latest@sha256:56418f03475cf7b107f87d7fabe99ce9a4a9f9904daafa99be7c50d9
|
||||
|
||||
ARG transporter_url=https://itunesconnect.apple.com/WebObjects/iTunesConnect.woa/ra/resources/download/public/Transporter__Linux/bin
|
||||
|
||||
RUN cargo install --locked --version 0.16.0 apple-codesign \
|
||||
RUN cargo install --locked --version 0.28.0 apple-codesign \
|
||||
&& curl -sSf $transporter_url -o transporter_install.sh \
|
||||
&& sh transporter_install.sh --target transporter --accept --noexec
|
||||
|
||||
|
||||
@@ -28,17 +28,17 @@ make fleetctl-docker
|
||||
|
||||
To sign and notarize a generated `pkg` you must have:
|
||||
|
||||
1. A Developer ID certificate in PEM format
|
||||
2. An Apple Store Connect API key
|
||||
1. A Developer ID Application certificate in PEM format
|
||||
2. An Apple Store Connect API key with App Manager access
|
||||
|
||||
> Note: the Developer ID certificate must be in PEM format because this image
|
||||
> can be run in automated environments where secrets are passed via environment
|
||||
> variables, and thus they must be in plain text.
|
||||
>
|
||||
> To convert a PKCS 12 certificate to PEM, you can run the following command:
|
||||
> To convert a DER (.cer) certificate to PEM, you can run the following command:
|
||||
>
|
||||
> ```
|
||||
> openssl pkcs12 -in /path/to/cert.p12 -out signing-keypair.pem -nodes
|
||||
> openssl x509 -inform der -outform pem -in developerID_application.cer -out developerID_application.pem
|
||||
> ```
|
||||
|
||||
Once you are set, you can build and notarize/staple your package with:
|
||||
|
||||
Reference in New Issue
Block a user