如何在无代码签名证书及signtool的情况下为PyInstaller生成的exe文件添加发布者名称
Hey there! I get it—you want your EXE to show a publisher name, but don't have a paid code signing cert or signtool. Let's break this down into two scenarios: adding the publisher name to the file properties (easy, no signing needed) and adding it via a self-signed digital signature (so Windows recognizes the publisher, even if it's untrusted).
Scenario 1: Add Publisher Name to File Properties (No Signing)
This will make the publisher name show up when you right-click the EXE → Properties → Details. No certificates required here—just tweak your PyInstaller spec file.
Generate a spec file (if you don't have one already):
pyinstaller --name your_app_name script.pyThis creates
your_app_name.specin your project folder.Edit the spec file to add version info with your publisher name:
Open the spec file in a text editor and add a version info dictionary, then link it to theEXEblock:# Add this at the top of the spec file version_info = { "CompanyName": "Your Publisher Name Here", # This maps to the "Publisher" field in properties "FileDescription": "Brief description of your app", "ProductName": "Your App's Full Name", "LegalCopyright": "© 2024 Your Name/Organization", "FileVersion": "1.0.0.0", "ProductVersion": "1.0.0" } # Find the EXE section and add the version parameter exe = EXE( pyz, a.scripts, a.binaries, a.zipfiles, a.datas, [], name='your_app_name', debug=False, bootloader_ignore_signals=False, strip=False, upx=True, upx_exclude=[], runtime_tmpdir=None, console=True, # Set to False if building a GUI app version=version_info, # Link the version info here )Rebuild the EXE using the modified spec file:
pyinstaller your_app_name.specNow check the EXE's properties—your publisher name will be listed under "Publisher"!
Scenario 2: Add a Self-Signed Digital Signature (For "Verified Publisher" Style)
If you want the publisher name to appear in Windows security prompts (even as an untrusted publisher), you'll need to sign the EXE with a self-signed certificate. Here's how to do it without signtool:
Step 1: Create a Self-Signed Certificate
We'll use OpenSSL (most systems have this pre-installed; if not, download it from the official OpenSSL site or use Chocolatey on Windows).
Generate a private key and certificate file:
openssl req -x509 -newkey rsa:4096 -keyout my_private_key.pem -out my_certificate.pem -days 365You'll be prompted to enter details—make sure the Common Name field is your publisher name (this is what will show up as the signed publisher).
Convert the certificate to a PFX file (a bundled format for key + cert, easier for signing):
openssl pkcs12 -export -out my_cert.pfx -inkey my_private_key.pem -in my_certificate.pemSet a password when prompted—you'll need this later to sign the EXE.
Step 2: Sign the EXE with osslsigncode
osslsigncode is a cross-platform tool that signs EXEs using Windows' Authenticode standard with OpenSSL certificates.
Install osslsigncode:
- On Windows: Use Chocolatey:
choco install osslsigncode - On macOS/Linux: Use your package manager (e.g.,
brew install osslsigncodeon macOS) or download binaries from its GitHub repo.
- On Windows: Use Chocolatey:
Sign your EXE:
Navigate to thedistfolder where your PyInstaller EXE is stored, then run:osslsigncode sign -pkcs12 my_cert.pfx -pass your_certificate_password -in your_app_name.exe -out your_app_name_signed.exe
Important Note About Self-Signed Certificates
Windows will flag your signed EXE as "Unknown Publisher" because it doesn't trust self-signed certs by default. To make it trusted on your own machine (or internal network), you can import the my_certificate.pem file into your Windows "Trusted Root Certification Authorities" store. For public distribution, you'll eventually need a paid certificate from a trusted CA like DigiCert or Sectigo.
内容的提问来源于stack exchange,提问作者Raj Mehta

