Apple Wallet Pass创建失败:icon.png SHA1哈希不匹配求助
Apple Wallet .pkpass 文件哈希不匹配错误
我用Bash脚本创建Apple Wallet的.pkpass文件,已完成所有步骤,反复检查了JSON、文件及文件大小,证书验证也有效。Manifest里的哈希值看起来是匹配的,但在模拟器运行时出现以下错误:
error 16:23:16.585688+1200 Passbook Invalid data error reading pass pass.com.whitelawmitchell.ToothCompany/p69f2J. For file icon.png, manifest's listed SHA1 hash gTWZcdeNNxGU1dceXF4lN5s9ono= doesn't match computed hash, 81359971d78d371194d5d71e5c5e25379b3da27a error 16:23:16.590540+1200 Passbook Failed to add pass: 'file:///Users/whitelawdesign/Documents/Personal/wallets/membership.pass/storecard.pkpass' Error Domain=PKPassKitErrorDomain Code=1 "The pass cannot be read because it isn’t valid." UserInfo={NSLocalizedDescription=The pass cannot be read because it isn’t valid., NSUnderlyingError=0x600000c556b0 {Error Domain=PKPassKitErrorDomain Code=1 "For file icon.png, manifest's listed SHA1 hash gTWZcdeNNxGU1dceXF4lN5s9ono= doesn't match computed hash, 81359971d78d371194d5d71e5c5e25379b3da27a" UserInfo={NSLocalizedDescription=For file icon.png, manifest's listed SHA1 hash gTWZcdeNNxGU1dceXF4lN5s9ono= doesn't match computed hash, 81359971d78d371194d5d71e5c5e25379b3da27a}}}.
我的脚本如下:
#!/bin/bash # Set variables P12_CERT="certificates.p12" CERT_PASSPHRASE="nikond60" PASS_TYPE_IDENTIFIER="pass.com.whitelawmitchell.ToothCompany" TEAM_IDENTIFIER="PSGZTYDDF5" CERT_PEM="certificate.pem" KEY_PEM="key.pem" KEY_NOENC_PEM="key-noenc.pem" WWDR_PEM="WWDR.pem" ROOT_CERT="AppleIncRootCertificate.pem" COMBINED_CA="combined-ca.pem" MANIFEST="manifest.json" SIGNATURE="signature" PKPASS_FILE="storecard.pkpass" # Extract certificate and key from the .p12 file echo "Extracting certificate and keys from .p12 file..." openssl pkcs12 -in "$P12_CERT" -clcerts -nokeys -out "$CERT_PEM" -passin pass:"$CERT_PASSPHRASE" -legacy openssl pkcs12 -in "$P12_CERT" -nocerts -out "$KEY_PEM" -passin pass:"$CERT_PASSPHRASE" -passout pass:"$CERT_PASSPHRASE" -legacy openssl rsa -in "$KEY_PEM" -out "$KEY_NOENC_PEM" -passin pass:"$CERT_PASSPHRASE" # Verify the extracted certificate echo "Verifying the certificate..." openssl verify -CAfile "$ROOT_CERT" -untrusted "$WWDR_PEM" "$CERT_PEM" # Create the manifest file echo "Creating manifest file..." cat <<EOF >"$MANIFEST" { "icon.png": "gTWZcdeNNxGU1dceXF4lN5s9ono=", "icon@2x.png": "Vu923Gp5gMx1K78+UTcDZllRXFQ=", "icon@3x.png": "PinMB32ggBF7G4DhxbP4IYMWvoQ=", "logo.png": "HBJLqdLz+q4iY4ZcZoAoiHrSB+o=", "strip.png": "345XiBA+L2wMKtknghkK9xN7Fi8=", "strip@2x.png": "bZQt2Dxlz+eG4NbOMOO+tiA1UzA=", "pass.json": "r/LAj6IgGhBBVSSnJsqPhvzyfZI=" } EOF # Create the combined CA file echo "Creating combined CA file..." cat "$CERT_PEM" "$WWDR_PEM" "$ROOT_CERT" > "$COMBINED_CA" # Sign the manifest file to create the signature echo "Signing the manifest file..." openssl smime -binary -sign -signer "$CERT_PEM" -inkey "$KEY_NOENC_PEM" -in "$MANIFEST" -outform DER -certfile "$COMBINED_CA" -out "$SIGNATURE" # Verify the signature echo "Verifying the signature..." openssl smime -verify -in "$SIGNATURE" -inform DER -content "$MANIFEST" -CAfile "$COMBINED_CA" -purpose any # Check if verification was successful if [ $? -ne 0 ]; then echo "Verification failed." exit 1 fi # Create the .pkpass file echo "Creating the .pkpass file..." zip -r "$PKPASS_FILE" pass.json "$MANIFEST" "$SIGNATURE" icon.png icon@2x.png icon@3x.png logo.png strip.png strip@2x.png # Verify the contents of the .pkpass file echo "Verifying the contents of the .pkpass file..." unzip -l "$PKPASS_FILE" echo "Process complete."
问题根源与解决步骤
核心问题
Manifest中的哈希值是手动写入的,而实际打包进pkpass的文件可能和计算哈希时的文件不一致(比如文件被修改、zip打包时自动添加了额外元数据),或者哈希计算方式不符合Apple要求。
解决步骤
自动生成Manifest哈希
替换脚本中手动生成manifest的部分,用命令自动计算每个文件的SHA1并编码为Base64,确保和实际文件匹配:# 替换原有的Create manifest file部分 echo "Creating manifest file..." > "$MANIFEST" echo "{" >> "$MANIFEST" first=1 for file in pass.json icon.png icon@2x.png icon@3x.png logo.png strip.png strip@2x.png; do if [ $first -ne 1 ]; then echo "," >> "$MANIFEST" fi hash=$(openssl sha1 -binary "$file" | base64) echo " \"$file\": \"$hash\"" >> "$MANIFEST" first=0 done echo "}" >> "$MANIFEST"确保zip打包无额外元数据
Apple要求pkpass中的文件不能包含额外的zip元数据,打包时添加-X参数禁用扩展属性,修改zip命令:zip -r -X "$PKPASS_FILE" pass.json "$MANIFEST" "$SIGNATURE" icon.png icon@2x.png icon@3x.png logo.png strip.png strip@2x.png验证哈希一致性
在打包前,手动验证icon.png的哈希是否和Manifest中的一致:openssl sha1 -binary icon.png | base64 # 对比输出是否和Manifest中icon.png的哈希值一致重新生成签名
每次修改Manifest后,必须重新签名,脚本中已经包含签名步骤,只要Manifest自动生成,签名会使用新的Manifest内容。
内容的提问来源于stack exchange,提问作者WhitelawMitchell
相关产品推荐
相关产品推荐

