使用GitHub Actions构建.NET MAUI 9应用时配置文件下载失败求助
.NET 9升级后GitHub Actions下载Apple Provisioning Profile失败(error:1E08010C:DECODER routines::unsupported)
问题详情
此前使用GitHub Actions YAML构建.NET MAUI应用并上传TestFlight一直正常,升级至.NET 9后,在Download Apple Provisioning Profiles步骤失败,报错:
Error: error:1E08010C:DECODER routines::unsupported
原YAML配置如下:
name: Build & Publish MyApp iOS on: pull_request: branches: [ "master" ] jobs: build-pack-n-ship: runs-on: macos-latest steps: - uses: maxim-lobanov/setup-xcode@v1 with: xcode-version: latest - uses: actions/checkout@v3 - name: Setup .NET uses: actions/setup-dotnet@v3 with: dotnet-version: 9.0.x - name: Install MAUI workload run: dotnet workload install maui - name: Import Code-Signing Certificates uses: Apple-Actions/import-codesign-certs@v1 with: p12-filepath: 'MyAppleDistributionCert.p12' p12-password: ${{ secrets.CERTIFICATES_P12_PASSWORD }} - name: Download Apple Provisioning Profiles uses: Apple-Actions/download-provisioning-profiles@v1 with: bundle-id: 'com.mycompany.myapp' issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }} api-key-id: ${{ secrets.APPSTORE_KEY_ID }} api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }} - name: Restore dependencies run: dotnet restore - name: Build and Publish run: dotnet publish -c Release -f:net9.0-ios /p:ArchiveOnBuild=true /p:EnableAssemblyILStripping=false - name: List generated files run: ls -l - name: Upload Build Artifact uses: actions/upload-artifact@v3.0.0 with: path: '**/*.ipa' - name: Archive dSYM files run: zip -r dSYMs.zip . -i ./MyApp/bin/Release/net9.0-ios/ios-arm64/*.app.dSYM - name: Upload dSYM Artifact uses: actions/upload-artifact@v3.0.0 with: name: dSYMs path: '**/dSYMs.zip' - name: 'Upload app to TestFlight' uses: apple-actions/upload-testflight-build@v1 with: app-path: './MyApp/bin/Release/net9.0-ios/ios-arm64/publish/MyApp.ipa' issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }} api-key-id: ${{ secrets.APPSTORE_KEY_ID }} api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }}
原因分析
该错误属于OpenSSL解码异常,核心诱因是:
- .NET 9对系统加密库的依赖版本与
macos-latestrunner上的默认环境、旧版Apple Actions工具链不兼容; - 指定
xcode-version: latest会拉取最新Xcode,其内置的加密库更新可能导致旧版Provisioning Profile下载工具无法适配密钥解码逻辑。
修复方案
1. 锁定兼容的Xcode版本
.NET 9 GA版本推荐搭配Xcode 15.4,避免使用latest带来的版本波动:
- uses: maxim-lobanov/setup-xcode@v1 with: xcode-version: '15.4'
2. 更新Apple Actions工具到最新稳定版
旧版Apple-Actions/download-provisioning-profiles@v1存在OpenSSL兼容性问题,升级到v2版本:
- name: Download Apple Provisioning Profiles uses: Apple-Actions/download-provisioning-profiles@v2 with: bundle-id: 'com.mycompany.myapp' issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }} api-key-id: ${{ secrets.APPSTORE_KEY_ID }} api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }}
同时同步更新其他Apple Actions工具:
- name: Import Code-Signing Certificates uses: Apple-Actions/import-codesign-certs@v2 with: p12-filepath: 'MyAppleDistributionCert.p12' p12-password: ${{ secrets.CERTIFICATES_P12_PASSWORD }} - name: 'Upload app to TestFlight' uses: apple-actions/upload-testflight-build@v2 with: app-path: './MyApp/bin/Release/net9.0-ios/ios-arm64/publish/MyApp.ipa' issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }} api-key-id: ${{ secrets.APPSTORE_KEY_ID }} api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }}
3. 验证API私钥格式
确保APPSTORE_PRIVATE_KEY的格式完全正确:
- 必须包含完整的
-----BEGIN PRIVATE KEY-----和-----END PRIVATE KEY-----标记; - 标记前后无多余空格或换行;
- 密钥内容本身无格式错误(可重新从Apple Developer后台导出复制)。
4. 固定.NET 9版本与更新setup-dotnet工具
使用具体的.NET 9稳定版本,并升级setup-dotnet到最新版:
- name: Setup .NET uses: actions/setup-dotnet@v4 with: dotnet-version: '9.0.100'
5. 添加OpenSSL兼容环境变量(可选)
若上述步骤仍未解决,在下载Provisioning Profile前添加环境变量配置:
- name: Configure OpenSSL Compatibility run: | export OPENSSL_CONF=/etc/ssl/
完整修改后的YAML示例
name: Build & Publish MyApp iOS on: pull_request: branches: [ "master" ] jobs: build-pack-n-ship: runs-on: macos-latest steps: - uses: maxim-lobanov/setup-xcode@v1 with: xcode-version: '15.4' - uses: actions/checkout@v4 # 更新到最新版checkout - name: Setup .NET uses: actions/setup-dotnet@v4 with: dotnet-version: '9.0.100' - name: Install MAUI workload run: dotnet workload install maui - name: Import Code-Signing Certificates uses: Apple-Actions/import-codesign-certs@v2 with: p12-filepath: 'MyAppleDistributionCert.p12' p12-password: ${{ secrets.CERTIFICATES_P12_PASSWORD }} - name: Configure OpenSSL Compatibility run: | export OPENSSL_CONF=/etc/ssl/ - name: Download Apple Provisioning Profiles uses: Apple-Actions/download-provisioning-profiles@v2 with: bundle-id: 'com.mycompany.myapp' issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }} api-key-id: ${{ secrets.APPSTORE_KEY_ID }} api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }} - name: Restore dependencies run: dotnet restore - name: Build and Publish run: dotnet publish -c Release -f:net9.0-ios /p:ArchiveOnBuild=true /p:EnableAssemblyILStripping=false - name: List generated files run: ls -l - name: Upload Build Artifact uses: actions/upload-artifact@v4 # 更新到最新版上传工具 with: path: '**/*.ipa' - name: Archive dSYM files run: zip -r dSYMs.zip . -i ./MyApp/bin/Release/net9.0-ios/ios-arm64/*.app.dSYM - name: Upload dSYM Artifact uses: actions/upload-artifact@v4 with: name: dSYMs path: '**/dSYMs.zip' - name: 'Upload app to TestFlight' uses: apple-actions/upload-testflight-build@v2 with: app-path: './MyApp/bin/Release/net9.0-ios/ios-arm64/publish/MyApp.ipa' issuer-id: ${{ secrets.APPSTORE_ISSUER_ID }} api-key-id: ${{ secrets.APPSTORE_KEY_ID }} api-private-key: ${{ secrets.APPSTORE_PRIVATE_KEY }}
内容的提问来源于stack exchange,提问作者Sam
相关产品推荐
相关产品推荐

