You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linux环境下使用YubiKey通过jsign签名EXE文件失败问题排查求助

Troubleshooting "Private Key Doesn't Match Certificate" Error with JSign & YubiKey

Let's break down why you're hitting this SignatureException and how to fix it:

The core issue here is that the private key stored on your YubiKey doesn't correspond to the user certificate in your all.crt file (or JSign is picking the wrong key/certificate pair from the YubiKey). Here's how to diagnose and resolve this step by step:

1. Verify the Public Key Match Between Your Certificate and YubiKey

First, confirm that the public key in your local my_certificate.crt matches the one paired with the private key on your YubiKey:

  • Extract the public key from your local certificate:
    openssl x509 -in my_certificate.crt -noout -pubkey
    
  • Export the certificate stored on your YubiKey and check its public key:
    1. List all certificates on your YubiKey to get the alias:
      keytool -list -storetype YUBIKEY -keystore NONE -storepass 123456
      
    2. Export the certificate using the alias you found:
      keytool -exportcert -alias "Your Certificate Alias" -storetype YUBIKEY -storepass 123456 -file yubikey_exported.crt
      
    3. Extract its public key:
      openssl x509 -in yubikey_exported.crt -noout -pubkey
      

Compare the two public key outputs—if they don't match, you're using the wrong local certificate (or the YubiKey has a different key pair than you think).

2. Ensure You're Targeting the Correct Certificate on the YubiKey

YubiKeys can store multiple certificates. If you have more than one, JSign might be picking the wrong one by default. Fix this by explicitly specifying the certificate alias in your JSign command:

jsign --storetype YUBIKEY --storepass 123456 --certfile all.crt --alias "Your Certificate Alias" unsigned.exe

Use the alias you found in the keytool -list step above.

3. Double-Check Your Certificate Chain File

While your cat command order (user cert → intermediate → root) is correct for Authenticode, make sure:

  • my_certificate.crt is exactly the certificate that was generated with the private key on your YubiKey (not a different one from your archive).
  • None of the certificates in all.crt are corrupted or truncated. You can verify the chain with:
    openssl verify -CAfile all.crt my_certificate.crt
    

This should return my_certificate.crt: OK if the chain is valid.

4. Confirm YubiKey PKCS#11 Compatibility

Ensure your system has the YubiKey PKCS#11 driver installed (usually libykcs11.so on Linux) and that JSign can access it. If you're having issues, you can explicitly specify the provider in your command:

jsign --storetype PKCS11 --storepass 123456 --providerclass sun.security.pkcs11.SunPKCS11 --providerarg yubikey.cfg --certfile all.crt --alias "Your Certificate Alias" unsigned.exe

Where yubikey.cfg contains:

name=YubiKey
library=/usr/lib/x86_64-linux-gnu/libykcs11.so

Adjust the library path to match your system's installation.


内容的提问来源于stack exchange,提问作者kamae

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 12:27:41