You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apple Wallet Pass创建失败:icon.png SHA1哈希不匹配求助

Apple Wallet .pkpass 文件哈希不匹配错误

我用Bash脚本创建Apple Wallet的.pkpass文件,已完成所有步骤,反复检查了JSON、文件及文件大小,证书验证也有效。Manifest里的哈希值看起来是匹配的,但在模拟器运行时出现以下错误:

error   16:23:16.585688+1200    Passbook    Invalid data error reading pass pass.com.whitelawmitchell.ToothCompany/p69f2J. For file icon.png, manifest's listed SHA1 hash gTWZcdeNNxGU1dceXF4lN5s9ono= doesn't match computed hash, 81359971d78d371194d5d71e5c5e25379b3da27a
error   16:23:16.590540+1200    Passbook    Failed to add pass: 'file:///Users/whitelawdesign/Documents/Personal/wallets/membership.pass/storecard.pkpass' Error Domain=PKPassKitErrorDomain Code=1 "The pass cannot be read because it isn’t valid." UserInfo={NSLocalizedDescription=The pass cannot be read because it isn’t valid., NSUnderlyingError=0x600000c556b0 {Error Domain=PKPassKitErrorDomain Code=1 "For file icon.png, manifest's listed SHA1 hash gTWZcdeNNxGU1dceXF4lN5s9ono= doesn't match computed hash, 81359971d78d371194d5d71e5c5e25379b3da27a" UserInfo={NSLocalizedDescription=For file icon.png, manifest's listed SHA1 hash gTWZcdeNNxGU1dceXF4lN5s9ono= doesn't match computed hash, 81359971d78d371194d5d71e5c5e25379b3da27a}}}.

我的脚本如下:

#!/bin/bash

# Set variables
P12_CERT="certificates.p12"
CERT_PASSPHRASE="nikond60"
PASS_TYPE_IDENTIFIER="pass.com.whitelawmitchell.ToothCompany"
TEAM_IDENTIFIER="PSGZTYDDF5"
CERT_PEM="certificate.pem"
KEY_PEM="key.pem"
KEY_NOENC_PEM="key-noenc.pem"
WWDR_PEM="WWDR.pem"
ROOT_CERT="AppleIncRootCertificate.pem"
COMBINED_CA="combined-ca.pem"
MANIFEST="manifest.json"
SIGNATURE="signature"
PKPASS_FILE="storecard.pkpass"

# Extract certificate and key from the .p12 file
echo "Extracting certificate and keys from .p12 file..."
openssl pkcs12 -in "$P12_CERT" -clcerts -nokeys -out "$CERT_PEM" -passin pass:"$CERT_PASSPHRASE" -legacy
openssl pkcs12 -in "$P12_CERT" -nocerts -out "$KEY_PEM" -passin pass:"$CERT_PASSPHRASE" -passout pass:"$CERT_PASSPHRASE" -legacy
openssl rsa -in "$KEY_PEM" -out "$KEY_NOENC_PEM" -passin pass:"$CERT_PASSPHRASE"

# Verify the extracted certificate
echo "Verifying the certificate..."
openssl verify -CAfile "$ROOT_CERT" -untrusted "$WWDR_PEM" "$CERT_PEM"

# Create the manifest file
echo "Creating manifest file..."
cat <<EOF >"$MANIFEST"
{
  "icon.png": "gTWZcdeNNxGU1dceXF4lN5s9ono=",
  "icon@2x.png": "Vu923Gp5gMx1K78+UTcDZllRXFQ=",
  "icon@3x.png": "PinMB32ggBF7G4DhxbP4IYMWvoQ=",
  "logo.png": "HBJLqdLz+q4iY4ZcZoAoiHrSB+o=",
  "strip.png": "345XiBA+L2wMKtknghkK9xN7Fi8=",
  "strip@2x.png": "bZQt2Dxlz+eG4NbOMOO+tiA1UzA=",
  "pass.json": "r/LAj6IgGhBBVSSnJsqPhvzyfZI="
}
EOF

# Create the combined CA file
echo "Creating combined CA file..."
cat "$CERT_PEM" "$WWDR_PEM" "$ROOT_CERT" > "$COMBINED_CA"

# Sign the manifest file to create the signature
echo "Signing the manifest file..."
openssl smime -binary -sign -signer "$CERT_PEM" -inkey "$KEY_NOENC_PEM" -in "$MANIFEST" -outform DER -certfile "$COMBINED_CA" -out "$SIGNATURE"

# Verify the signature
echo "Verifying the signature..."
openssl smime -verify -in "$SIGNATURE" -inform DER -content "$MANIFEST" -CAfile "$COMBINED_CA" -purpose any

# Check if verification was successful
if [ $? -ne 0 ]; then
  echo "Verification failed."
  exit 1
fi

# Create the .pkpass file
echo "Creating the .pkpass file..."
zip -r "$PKPASS_FILE" pass.json "$MANIFEST" "$SIGNATURE" icon.png icon@2x.png icon@3x.png logo.png strip.png strip@2x.png

# Verify the contents of the .pkpass file
echo "Verifying the contents of the .pkpass file..."
unzip -l "$PKPASS_FILE"

echo "Process complete."

问题根源与解决步骤

核心问题

Manifest中的哈希值是手动写入的,而实际打包进pkpass的文件可能和计算哈希时的文件不一致(比如文件被修改、zip打包时自动添加了额外元数据),或者哈希计算方式不符合Apple要求。

解决步骤

  1. 自动生成Manifest哈希
    替换脚本中手动生成manifest的部分,用命令自动计算每个文件的SHA1并编码为Base64,确保和实际文件匹配:

    # 替换原有的Create manifest file部分
    echo "Creating manifest file..."
    > "$MANIFEST"
    echo "{" >> "$MANIFEST"
    first=1
    for file in pass.json icon.png icon@2x.png icon@3x.png logo.png strip.png strip@2x.png; do
        if [ $first -ne 1 ]; then
            echo "," >> "$MANIFEST"
        fi
        hash=$(openssl sha1 -binary "$file" | base64)
        echo "  \"$file\": \"$hash\"" >> "$MANIFEST"
        first=0
    done
    echo "}" >> "$MANIFEST"
    
  2. 确保zip打包无额外元数据
    Apple要求pkpass中的文件不能包含额外的zip元数据,打包时添加-X参数禁用扩展属性,修改zip命令:

    zip -r -X "$PKPASS_FILE" pass.json "$MANIFEST" "$SIGNATURE" icon.png icon@2x.png icon@3x.png logo.png strip.png strip@2x.png
    
  3. 验证哈希一致性
    在打包前,手动验证icon.png的哈希是否和Manifest中的一致:

    openssl sha1 -binary icon.png | base64
    # 对比输出是否和Manifest中icon.png的哈希值一致
    
  4. 重新生成签名
    每次修改Manifest后,必须重新签名,脚本中已经包含签名步骤,只要Manifest自动生成,签名会使用新的Manifest内容。

内容的提问来源于stack exchange,提问作者WhitelawMitchell

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 19:14:53