Skip to content

signing identity: an import macOS accepts - #8

Open
mcouzinet wants to merge 2 commits into
fdussert:mainfrom
mcouzinet:signing-identity-import
Open

mcouzinet wants to merge 2 commits into
fdussert:mainfrom
mcouzinet:signing-identity-import

Conversation

@mcouzinet

Copy link
Copy Markdown
Contributor

scripts/create-signing-identity.sh fails on this Mac (macOS 15, Homebrew in the PATH):

==> packaging them as PKCS#12
==> importing into the login keychain
security: SecKeychainItemImport: MAC verification failed during PKCS12 import (wrong password?)

set -e stops there, so no identity is created. Every build of the helper afterwards stays ad-hoc signed, gets a new code identity, and drops the Input Monitoring and Accessibility grants of the build before. That is how it reached me: the touch panel stopped working and started clicking on another display, because macOS maps a panel no driver claims to the main one. The message blames a password, which is not where the problem is.

Two causes, checked one at a time against a throwaway keychain (security create-keychain, import, delete-keychain):

bundle written by password security import
/usr/bin/openssl (LibreSSL 3.3.6) empty fails
Homebrew openssl (3.6.3) empty fails
Homebrew openssl (3.6.3) non-empty fails
/usr/bin/openssl (LibreSSL 3.3.6) non-empty works

So the script now uses a throwaway password (kept in the script, never written anywhere), and asks for /usr/bin/openssl by name, keeping openssl from the PATH as the fallback. The -legacy attempt in front of the old command is gone: it covers exactly the case that Homebrew's build cannot do, since it ships no legacy provider.

Verified by running the patched script end to end against a temporary keychain, with the trust and partition-list steps stubbed out (they prompt for the login password): the import passes and the certificate is in the keychain. The two stubbed steps are unchanged.

One line in the CHANGELOG, under Fixed, since what the user notices is the helper losing its permissions.

🤖 Generated with Claude Code

`security import` refused the bundle the script writes, with "MAC
verification failed during PKCS12 import (wrong password?)", and the
identity was never created. Every later build of the helper then stayed
ad-hoc signed, which gives it a new code identity each time and drops
the Input Monitoring and Accessibility grants of the build before. What
the user sees is the touch panel gone: macOS maps the untouched panel
to the main display, so the Edge clicks on another screen.

Two causes, both on current macOS, and the message names neither.

The bundle is written with an empty password, which the Security
framework no longer verifies, whatever wrote it: a throwaway password
is enough, and it never leaves the script.

And `openssl` was whatever the PATH offered first, which on a Mac with
Homebrew is OpenSSL 3: it packages the bundle with algorithms
`security` does not read, and the `-legacy` attempt in front of it
needs a provider that build does not ship, so the fallback wrote an
unreadable bundle every time. macOS always has LibreSSL at
/usr/bin/openssl, which writes what its own tools accept, so the script
asks for it by name and keeps `openssl` as the fallback.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@mcouzinet
mcouzinet force-pushed the signing-identity-import branch from 658b506 to 8e9f9bb Compare September 28, 2026 08:56
Re-adding the helper under Privacy & Security does not help when the
identity changed: macOS keeps one entry per past signature, ticked and
useless, and matches those before the new one. It took a `tccutil
reset` of both services on my Mac, which had three of each, to get the
prompts back and the touch panel with them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant