You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Set-AuthenticodeSignature修改UAC中MSI安装包的临时名称?

解决Wix MSI用Set-AuthenticodeSignature签名后UAC弹窗显示随机名称的问题

核心原因

UAC弹窗显示的名称优先读取数字签名中的文档描述(对应SignTool的/d参数);如果签名中无该信息,会 fallback 到MSI文件的摘要信息流中的Description字段;若两者都缺失,才会显示临时随机文件名。Set-AuthenticodeSignature cmdlet本身没有直接设置描述的参数,但可以通过两种间接方式解决:


方法1:配置Wix MSI的摘要描述(优先推荐)

直接在Wix的Product元素中设置Description属性,该值会写入MSI的摘要信息流,Windows Installer会优先用它作为UAC显示名称:

<Product 
    Id="*" 
    Name="你的软件名称" 
    Language="1033" 
    Version="1.0.0.0" 
    Manufacturer="你的公司" 
    UpgradeCode="PUT-YOUR-GUID-HERE"
    Description="XX软件正式版安装包" <!-- 这里设置UAC要显示的名称 -->
>
    <!-- 其他Wix配置 -->
</Product>

编译生成MSI后,可通过以下命令验证摘要描述是否生效:

Get-ItemProperty -Path "path\to\your.msi" | Select-Object -ExpandProperty VersionInfo

方法2:用.NET底层API手动添加签名描述

如果必须通过签名本身设置描述,可以绕过Set-AuthenticodeSignature cmdlet,直接调用.NET的Pkcs API在签名时添加Pkcs9DocumentDescription属性。示例PowerShell脚本:

$msiPath = "C:\build\your-installer.msi"
$pfxPath = "C:\certs\code-signing.pfx"
$pfxPassword = ConvertTo-SecureString "your-cert-password" -AsPlainText -Force

# 加载代码签名证书
$cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2($pfxPath, $pfxPassword, [System.Security.Cryptography.X509Certificates.X509KeyStorageFlags]::Exportable)

# 打开MSI文件流
$fileStream = New-Object System.IO.FileStream($msiPath, [System.IO.FileMode]::Open, [System.IO.FileAccess]::ReadWrite)
try {
    # 创建CMS签名对象
    $contentInfo = [System.Security.Cryptography.Pkcs.ContentInfo]::CreateFromFile($fileStream)
    $signedCms = New-Object System.Security.Cryptography.Pkcs.SignedCms($contentInfo, $false)
    
    # 配置签名者并添加描述属性
    $cmsSigner = New-Object System.Security.Cryptography.Pkcs.CmsSigner($cert)
    $descriptionAttr = New-Object System.Security.Cryptography.Pkcs.Pkcs9DocumentDescription("XX软件正式版安装包")
    $cmsSigner.SignedAttributes.Add($descriptionAttr)
    
    # 计算并写入签名
    $signedCms.ComputeSignature($cmsSigner)
    $fileStream.Position = 0
    $signedCms.EncodeToStream($fileStream)
}
finally {
    $fileStream.Close()
}

签名完成后,用以下命令验证签名描述是否存在:

signtool verify /v /pa $msiPath

确认输出中包含Description: XX软件正式版安装包即可。


内容的提问来源于stack exchange,提问作者VassilisM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 07:00:19