Linux环境下使用YubiKey通过jsign签名EXE文件失败问题排查求助
Let's break down why you're hitting this SignatureException and how to fix it:
The core issue here is that the private key stored on your YubiKey doesn't correspond to the user certificate in your all.crt file (or JSign is picking the wrong key/certificate pair from the YubiKey). Here's how to diagnose and resolve this step by step:
1. Verify the Public Key Match Between Your Certificate and YubiKey
First, confirm that the public key in your local my_certificate.crt matches the one paired with the private key on your YubiKey:
- Extract the public key from your local certificate:
openssl x509 -in my_certificate.crt -noout -pubkey - Export the certificate stored on your YubiKey and check its public key:
- List all certificates on your YubiKey to get the alias:
keytool -list -storetype YUBIKEY -keystore NONE -storepass 123456 - Export the certificate using the alias you found:
keytool -exportcert -alias "Your Certificate Alias" -storetype YUBIKEY -storepass 123456 -file yubikey_exported.crt - Extract its public key:
openssl x509 -in yubikey_exported.crt -noout -pubkey
- List all certificates on your YubiKey to get the alias:
Compare the two public key outputs—if they don't match, you're using the wrong local certificate (or the YubiKey has a different key pair than you think).
2. Ensure You're Targeting the Correct Certificate on the YubiKey
YubiKeys can store multiple certificates. If you have more than one, JSign might be picking the wrong one by default. Fix this by explicitly specifying the certificate alias in your JSign command:
jsign --storetype YUBIKEY --storepass 123456 --certfile all.crt --alias "Your Certificate Alias" unsigned.exe
Use the alias you found in the keytool -list step above.
3. Double-Check Your Certificate Chain File
While your cat command order (user cert → intermediate → root) is correct for Authenticode, make sure:
my_certificate.crtis exactly the certificate that was generated with the private key on your YubiKey (not a different one from your archive).- None of the certificates in
all.crtare corrupted or truncated. You can verify the chain with:openssl verify -CAfile all.crt my_certificate.crt
This should return my_certificate.crt: OK if the chain is valid.
4. Confirm YubiKey PKCS#11 Compatibility
Ensure your system has the YubiKey PKCS#11 driver installed (usually libykcs11.so on Linux) and that JSign can access it. If you're having issues, you can explicitly specify the provider in your command:
jsign --storetype PKCS11 --storepass 123456 --providerclass sun.security.pkcs11.SunPKCS11 --providerarg yubikey.cfg --certfile all.crt --alias "Your Certificate Alias" unsigned.exe
Where yubikey.cfg contains:
name=YubiKey library=/usr/lib/x86_64-linux-gnu/libykcs11.so
Adjust the library path to match your system's installation.
内容的提问来源于stack exchange,提问作者kamae

