Conversation
`security import` refused the bundle the script writes, with "MAC verification failed during PKCS12 import (wrong password?)", and the identity was never created. Every later build of the helper then stayed ad-hoc signed, which gives it a new code identity each time and drops the Input Monitoring and Accessibility grants of the build before. What the user sees is the touch panel gone: macOS maps the untouched panel to the main display, so the Edge clicks on another screen. Two causes, both on current macOS, and the message names neither. The bundle is written with an empty password, which the Security framework no longer verifies, whatever wrote it: a throwaway password is enough, and it never leaves the script. And `openssl` was whatever the PATH offered first, which on a Mac with Homebrew is OpenSSL 3: it packages the bundle with algorithms `security` does not read, and the `-legacy` attempt in front of it needs a provider that build does not ship, so the fallback wrote an unreadable bundle every time. macOS always has LibreSSL at /usr/bin/openssl, which writes what its own tools accept, so the script asks for it by name and keeps `openssl` as the fallback. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
mcouzinet
force-pushed
the
signing-identity-import
branch
from
September 28, 2026 08:56
658b506 to
8e9f9bb
Compare
Re-adding the helper under Privacy & Security does not help when the identity changed: macOS keeps one entry per past signature, ticked and useless, and matches those before the new one. It took a `tccutil reset` of both services on my Mac, which had three of each, to get the prompts back and the touch panel with them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
scripts/create-signing-identity.shfails on this Mac (macOS 15, Homebrew in the PATH):set -estops there, so no identity is created. Every build of the helper afterwards stays ad-hoc signed, gets a new code identity, and drops the Input Monitoring and Accessibility grants of the build before. That is how it reached me: the touch panel stopped working and started clicking on another display, because macOS maps a panel no driver claims to the main one. The message blames a password, which is not where the problem is.Two causes, checked one at a time against a throwaway keychain (
security create-keychain, import,delete-keychain):security import/usr/bin/openssl(LibreSSL 3.3.6)openssl(3.6.3)openssl(3.6.3)/usr/bin/openssl(LibreSSL 3.3.6)So the script now uses a throwaway password (kept in the script, never written anywhere), and asks for
/usr/bin/opensslby name, keepingopensslfrom the PATH as the fallback. The-legacyattempt in front of the old command is gone: it covers exactly the case that Homebrew's build cannot do, since it ships no legacy provider.Verified by running the patched script end to end against a temporary keychain, with the trust and partition-list steps stubbed out (they prompt for the login password): the import passes and the certificate is in the keychain. The two stubbed steps are unchanged.
One line in the CHANGELOG, under Fixed, since what the user notices is the helper losing its permissions.
🤖 Generated with Claude Code