You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell代码签名证书未知错误求助:签名脚本执行及运行故障排查

Troubleshooting "Unknown Signature Certificate Error" in PowerShell Script Signing

First, let's clear up your initial question: you don't need to set all execution policies to AllSigned. PowerShell applies execution policies in a priority order, and your CurrentUser setting of AllSigned is sufficient for your scenario—this isn't the root cause of your error.

Now, let's dive into troubleshooting the "unknown signature certificate error" you're facing, even after redoing the certificate setup per Microsoft's docs:

  • Verify your code-signing certificate is valid
    Run this command to check key details of your certificate:

    Get-ChildItem cert:\CurrentUser\My -codesigning | Select-Object Subject, NotAfter, Status, HasPrivateKey
    

    Ensure:

    • The Status shows "Valid" (no revocation or expiration issues)
    • NotAfter is a future date
    • HasPrivateKey is True (without a private key, you can't sign anything)
  • Check private key permissions
    Sometimes the private key associated with your certificate doesn't have the right permissions for your admin user:

    1. Open certmgr.msc and navigate to Current User > Personal > Certificates
    2. Right-click your code-signing certificate > All Tasks > Manage Private Keys
    3. Make sure your admin account has Read permissions (add it if missing)
  • Avoid index-based certificate selection
    Using [0] to pick the first certificate might be selecting the wrong one (even if you deleted old certs, sometimes residual entries stick). Instead, target the certificate explicitly by its subject or thumbprint:

    # Replace "Your Certificate Subject" with the actual subject from your cert
    $cert = Get-ChildItem cert:\CurrentUser\My -codesigning | Where-Object { $_.Subject -match "Your Certificate Subject" }
    Set-AuthenticodeSignature .\add-signature.ps1 $cert
    
  • Unblock the script file
    If the add-signature.ps1 was downloaded from the internet or copied from a network location, Windows might have marked it as blocked, which can interfere with signing:

    Unblock-File -Path .\add-signature.ps1
    
  • Enable verbose logging for more details
    Run the signing command with the -Verbose flag to get granular error info that might point to the exact issue (e.g., certificate chain problems, unsupported hash algorithms):

    Set-AuthenticodeSignature .\add-signature.ps1 $cert -Verbose
    
  • Test with PowerShell 7+
    Older versions of Windows PowerShell (5.1 and below) have limited support for modern certificate types. Try installing PowerShell 7 and running the signing commands there—this often resolves compatibility issues.

Work through these steps one by one, and the verbose output should give you a clearer picture if the problem persists.

内容的提问来源于stack exchange,提问作者MarcusR1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 20:02:45