You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用InnoSetup(ISCC.exe)与DigiCert smctl.exe签名卸载程序失败求助

问题:InnoSetup启用SignedUninstaller=yes时签名失败

1. 当前配置

调用ISCC.exe的命令:

/Dsigning=true /Dbuildworkingdir=${bamboo.build.working.directory} ${bamboo.build.working.directory}\150_Software\10_SW\InnoSetup\EPCSetup.iss "/Ssigntool=smctl.exe sign --keypair-alias key_XXXXXXXX --input $f"

当SignedUninstaller=no时,可正常生成签名有效的setup.exe。

2. 问题现象

设置SignedUninstaller=yes后构建失败,Bamboo日志如下:

build 27-Sep-2023 08:09:20 Preparing Setup program executable
build 27-Sep-2023 08:09:20 Updating version info (SETUP.E32)
build 27-Sep-2023 08:09:21 Running Sign Tool signtool: C:\Program Files\DigiCert\DigiCert Keylocker Tools\smctl.exe sign --keypair-alias key_XXXXXXXXX --input "D:\Atlassian\ApplicationData\Bamboo\local-working-dir\360449\CFN-DIG-JOB1\150_Software\10_SW\InnoSetup\Output\uninst.e32.tmp"
build 27-Sep-2023 08:09:24 There were no files found for signing
error 27-Sep-2023 08:09:24 Error in D:\Atlassian\ApplicationData\Bamboo\local-working-dir\360449\CFN-DIG-JOB1\150_Software\10_SW\InnoSetup\EPCSetup.iss: The Sign Tool command returned an exit code of 0, but the file does not have a digital signature.
error 27-Sep-2023 08:09:24 Compile aborted.

3. 排查情况

  • smctl.exe依赖Microsoft signtool.exe完成签名,而signtool.exe仅支持签名可执行文件
  • InnoSetup尝试签名uninst.e32.tmp临时文件,但smctl.exe拒绝处理该文件

4. 疑问与求助

  • 为何InnoSetup要签名*.tmp临时文件?
  • 如何解决启用SignedUninstaller=yes时的签名失败问题?

解决提示

  • 理解临时文件签名逻辑:uninst.e32.tmp是卸载程序编译过程中的PE格式临时可执行文件,InnoSetup生成最终uninst.exe前会先处理该文件,启用SignedUninstaller=yes时会触发签名流程。
  • 调整smctl命令参数:检查smctl.exe是否需要显式指定文件类型,或添加兼容.tmp后缀可执行文件的参数,确保--input能正确识别该临时文件的PE属性。
  • 绕过内置签名,手动签最终文件:放弃使用InnoSetup的SignedUninstaller选项,改为编译完成后单独签名卸载程序:
    1. 保持SignedUninstaller=no
    2. 新增构建步骤,执行签名命令:
      smctl.exe sign --keypair-alias key_XXXXXXXX --input "${bamboo.build.working.directory}\150_Software\10_SW\InnoSetup\Output\uninst.exe"
      
  • 修正smctl返回值判断:日志显示smctl返回0但未完成签名,说明其对无效文件的错误处理存在问题。可在签名后添加验证步骤,比如用signtool verify /pa <文件路径>确认签名状态,验证失败则终止构建。
  • 确认临时文件有效性:手动检查uninst.e32.tmp是否为有效PE文件,比如用dumpbin /headers命令查看,确保signtool.exe能正常识别。

内容的提问来源于stack exchange,提问作者ebiondi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 04:15:27