You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何导出Sectigo代码签名证书为PFX?Electron Forge签名及CI问题求助

代码签名问题:从Sectigo USB密钥导出PFX并完成Electron Forge签名

我正在开发一款Electron Forge应用,希望以LLC身份签名应用,避免用户运行exe时出现“未知开发者”弹窗(该提示会带来糟糕的用户体验)。我需要从Sectigo USB密钥中导出PFX文件,以便通过GitHub Action完成应用签名(过去并非必须使用USB设备)。

预期流程

根据Electron Forge文档,我预期的步骤为:

  • 从Sectigo购买代码签名证书并完成验证流程(我购买的是非EV版本);
  • 插入存储签名证书的USB设备;
  • 获取邮件中的密码;
  • 导出PFX文件;
  • 更新forge.config.js配置:
{
      name: '@electron-forge/maker-squirrel',
      config: {
        certificateFile: './cert.pfx', // <- 我需要此PFX文件
        certificatePassword: process.env.CERTIFICATE_PASSWORD // <- 我认为这是邮件中的密码
      }
    }

尝试过的PFX导出方法

Sectigo知识库导航难度大,未找到匹配我场景的PFX导出示例。以下是我的尝试:

使用SafeNet Authentication Client

  • 下载并打开Sectigo推荐的SafeNet Authentication Client;
  • 查看层级结构:Tokens -> My Company LLC -> User Certificates -> My Company LLC;
  • 使用邮件中的密码登录外层My Company LLC令牌;
  • 右键点击内层My Company LLC令牌选择导出;
  • 仅支持导出.cer格式,无法获取所需的.pfx文件。

使用certmgr.msc

  • 运行certmgr.msc(注意:Windows搜索“证书管理器”打开的应用显示的证书不同,原因未知);
  • 找到由Sectigo Public Code Signing CA R36颁发的My Company LLC证书;
  • 右键选择“所有任务”->“导出”,点击下一步;
  • “是,导出私钥”选项为灰色不可用;
  • 提示:“注意:关联的私钥标记为不可导出。仅可导出证书。”

手动签名尝试

  • 运行certmgr.msc;
  • 双击My Company LLC证书,进入“详细信息”页,复制Thumbprint字段值;
  • 将signtool添加至系统路径;
  • 运行make生成Electron Forge exe文件;
  • 在管理员bash中执行命令:
signtool sign /sha1 THUMBPRINT_OF_CERTIFICATE /tr http://timestamp.sectigo.com /td sha256 /fd sha256 /ksp "SafeNet Key Storage Provider" "path\to\program.exe"

执行后报错:

SignTool Error: Multiple certificates were found that meet all the given
        criteria. Use the /a option to allow SignTool to choose the best
        certificate automatically or use the /sha1 option with the hash of the
        desired certificate.
The following certificates meet all given criteria:
    Issued to: 12a07552-4d30-4fca-846c-a8be84912193
    Issued by: 12a07552-4d30-4fca-846c-a8be84912193
    Expires:   Sat Mar 29 01:32:52 2025
    SHA1 hash: HASH_ONE

    Issued to: 2f31b0a3-ea27-4cd2-9667-2b0d00c33f1d
    Issued by: 2f31b0a3-ea27-4cd2-9667-2b0d00c33f1d
    Expires:   Tue Mar 25 20:44:51 2025
    SHA1 hash: HASH_TWO

    Issued to: MY COMPANY LLC
    Issued by: Sectigo Public Code Signing CA R36
    Expires:   Thu May 22 18:59:59 2025
    SHA1 hash: MY_CERTIFICATE_THUMBPRINT

即使添加了/a和/sha1参数,仍出现上述错误。

物理设备要求疑问

我了解到微软现在要求使用物理设备签名应用,这是否意味着无法通过CI(持续集成)签名应用?手动构建应用会增加大量人为错误。

密钥截图

My Token
My Certificate


内容的提问来源于stack exchange,提问作者Oliver Barnum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 04:32:22