You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查找已签名Jar文件的发布者及验证可信签名归属?

Hey there! Since you already know how to use jarsigner to validate your JAR's signature, let's walk through how to dig up the publisher info and confirm if the certificate is trusted and compliant.

1. Locate the JAR's Publisher

To pull out the publisher's details, use the jarsigner command with verbose and certificate flags—this will dump all the signature and certificate metadata you need:

jarsigner -verify -verbose -certs yourJarFile.jar

In the output, look for sections labeled Signer #X (if there are multiple signatures on the JAR). Under each signer block, the Owner field will show the publisher's full distinguished name (DN)—this includes details like their organization name, country, and common name. For example:

Owner: CN=Example Corp, OU=Engineering, O=Example Inc, L=New York, ST=NY, C=US

The Issuer field directly below it tells you which certificate authority (CA) issued the publisher's certificate—this is critical for checking trust later on.

2. Verify if the Certificate is Trusted & Compliant

Validating the signature is only half the battle; confirming the certificate comes from a trusted, compliant source requires a few extra checks:

Check the Certificate Chain Trust

Java uses a default truststore (located at $JAVA_HOME/jre/lib/security/cacerts on most systems) that contains pre-trusted root CAs. For the certificate to be fully trusted, its entire chain (from the publisher's cert up to a root CA) must exist in this store.

  • Use keytool to search for the issuer CA in the truststore:
    keytool -list -keystore $JAVA_HOME/jre/lib/security/cacerts | grep -i "issuer-common-name"
    
    Replace issuer-common-name with the CN value from the Issuer field in your jarsigner output. If the issuer appears in the results, the root CA is trusted by your Java environment.

Validate Certificate Compliance

Even if the chain is trusted, you should confirm the certificate is explicitly authorized for code signing (some CAs issue certificates for specific purposes only):

  • Use keytool to print the full certificate details directly from the JAR:
    keytool -printcert -jarfile yourJarFile.jar
    
    Look for the Extended Key Usage section—you should see Code Signing listed here. This confirms the certificate was issued specifically for signing JAR files.
  • Also check the Valid from and Valid until dates to ensure the certificate wasn't expired when the JAR was signed, and isn't expired currently.

Quick Visual Inspection (Optional)

If you prefer a graphical view of the certificate details:

  1. Run jarsigner -verify -verbose -certs yourJarFile.jar > jar_signature_details.txt to save the output to a file.
  2. Copy the block of text starting with -----BEGIN CERTIFICATE----- and ending with -----END CERTIFICATE----- for the publisher's certificate.
  3. Paste this into a new file named publisher_cert.crt.
  4. Open the file with your system's certificate viewer (Windows Certificate Manager, Mac Keychain Access, or Linux's certificate tool)—it will clearly show the trust status, issuer details, and intended purpose of the certificate.

Note on Self-Signed or Untrusted Certs

If jarsigner validates the signature but the certificate isn't in the default truststore, it's likely a self-signed certificate or issued by an untrusted CA. In this case, you'll need to manually confirm if you trust the publisher before relying on the JAR's integrity.

内容的提问来源于stack exchange,提问作者Srikar Durgi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 13:27:33