PowerShell代码签名证书未知错误求助:签名脚本执行及运行故障排查
First, let's clear up your initial question: you don't need to set all execution policies to AllSigned. PowerShell applies execution policies in a priority order, and your CurrentUser setting of AllSigned is sufficient for your scenario—this isn't the root cause of your error.
Now, let's dive into troubleshooting the "unknown signature certificate error" you're facing, even after redoing the certificate setup per Microsoft's docs:
Verify your code-signing certificate is valid
Run this command to check key details of your certificate:Get-ChildItem cert:\CurrentUser\My -codesigning | Select-Object Subject, NotAfter, Status, HasPrivateKeyEnsure:
- The
Statusshows "Valid" (no revocation or expiration issues) NotAfteris a future dateHasPrivateKeyisTrue(without a private key, you can't sign anything)
- The
Check private key permissions
Sometimes the private key associated with your certificate doesn't have the right permissions for your admin user:- Open
certmgr.mscand navigate to Current User > Personal > Certificates - Right-click your code-signing certificate > All Tasks > Manage Private Keys
- Make sure your admin account has Read permissions (add it if missing)
- Open
Avoid index-based certificate selection
Using[0]to pick the first certificate might be selecting the wrong one (even if you deleted old certs, sometimes residual entries stick). Instead, target the certificate explicitly by its subject or thumbprint:# Replace "Your Certificate Subject" with the actual subject from your cert $cert = Get-ChildItem cert:\CurrentUser\My -codesigning | Where-Object { $_.Subject -match "Your Certificate Subject" } Set-AuthenticodeSignature .\add-signature.ps1 $certUnblock the script file
If theadd-signature.ps1was downloaded from the internet or copied from a network location, Windows might have marked it as blocked, which can interfere with signing:Unblock-File -Path .\add-signature.ps1Enable verbose logging for more details
Run the signing command with the-Verboseflag to get granular error info that might point to the exact issue (e.g., certificate chain problems, unsupported hash algorithms):Set-AuthenticodeSignature .\add-signature.ps1 $cert -VerboseTest with PowerShell 7+
Older versions of Windows PowerShell (5.1 and below) have limited support for modern certificate types. Try installing PowerShell 7 and running the signing commands there—this often resolves compatibility issues.
Work through these steps one by one, and the verbose output should give you a clearer picture if the problem persists.
内容的提问来源于stack exchange,提问作者MarcusR1

