如何查找已签名Jar文件的发布者及验证可信签名归属?
Hey there! Since you already know how to use jarsigner to validate your JAR's signature, let's walk through how to dig up the publisher info and confirm if the certificate is trusted and compliant.
To pull out the publisher's details, use the jarsigner command with verbose and certificate flags—this will dump all the signature and certificate metadata you need:
jarsigner -verify -verbose -certs yourJarFile.jar
In the output, look for sections labeled Signer #X (if there are multiple signatures on the JAR). Under each signer block, the Owner field will show the publisher's full distinguished name (DN)—this includes details like their organization name, country, and common name. For example:
Owner: CN=Example Corp, OU=Engineering, O=Example Inc, L=New York, ST=NY, C=US
The Issuer field directly below it tells you which certificate authority (CA) issued the publisher's certificate—this is critical for checking trust later on.
Validating the signature is only half the battle; confirming the certificate comes from a trusted, compliant source requires a few extra checks:
Check the Certificate Chain Trust
Java uses a default truststore (located at $JAVA_HOME/jre/lib/security/cacerts on most systems) that contains pre-trusted root CAs. For the certificate to be fully trusted, its entire chain (from the publisher's cert up to a root CA) must exist in this store.
- Use
keytoolto search for the issuer CA in the truststore:
Replacekeytool -list -keystore $JAVA_HOME/jre/lib/security/cacerts | grep -i "issuer-common-name"issuer-common-namewith the CN value from theIssuerfield in yourjarsigneroutput. If the issuer appears in the results, the root CA is trusted by your Java environment.
Validate Certificate Compliance
Even if the chain is trusted, you should confirm the certificate is explicitly authorized for code signing (some CAs issue certificates for specific purposes only):
- Use
keytoolto print the full certificate details directly from the JAR:
Look for thekeytool -printcert -jarfile yourJarFile.jarExtended Key Usagesection—you should seeCode Signinglisted here. This confirms the certificate was issued specifically for signing JAR files. - Also check the
Valid fromandValid untildates to ensure the certificate wasn't expired when the JAR was signed, and isn't expired currently.
Quick Visual Inspection (Optional)
If you prefer a graphical view of the certificate details:
- Run
jarsigner -verify -verbose -certs yourJarFile.jar > jar_signature_details.txtto save the output to a file. - Copy the block of text starting with
-----BEGIN CERTIFICATE-----and ending with-----END CERTIFICATE-----for the publisher's certificate. - Paste this into a new file named
publisher_cert.crt. - Open the file with your system's certificate viewer (Windows Certificate Manager, Mac Keychain Access, or Linux's certificate tool)—it will clearly show the trust status, issuer details, and intended purpose of the certificate.
Note on Self-Signed or Untrusted Certs
If jarsigner validates the signature but the certificate isn't in the default truststore, it's likely a self-signed certificate or issued by an untrusted CA. In this case, you'll need to manually confirm if you trust the publisher before relying on the JAR's integrity.
内容的提问来源于stack exchange,提问作者Srikar Durgi

