MacOS Eclipse RCP应用公证:寻求Maven签名插件方案
针对Eclipse RCP应用Tycho构建的签名方案
你可以用以下两个Maven插件在产品安装完成、生成压缩包前完成签名:
1. maven-exec-plugin(最灵活直接)
直接调用macOS原生的codesign命令,完全可控,适配任何Tycho构建流程。把它绑定在tycho-p2-director-plugin:materialize-products之后、打包插件(比如tycho-p2-repository-plugin或maven-assembly-plugin)之前的构建阶段。
配置示例:
<plugin> <groupId>org.codehaus.mojo</groupId> <artifactId>exec-maven-plugin</artifactId> <version>3.1.0</version> <executions> <execution> <id>codesign-app</id> <phase>prepare-package</phase> <goals> <goal>exec</goal> </goals> <configuration> <executable>codesign</executable> <arguments> <argument>--force</argument> <argument>--deep</argument> <argument>--sign</argument> <argument>你的开发者签名身份(比如"Developer ID Application: XXX")</argument> <argument>${project.build.directory}/products/你的应用名称.app</argument> </arguments> </configuration> </execution> </executions> </plugin>
--force:覆盖.app模板原来的旧签名--deep:递归签名.app内部所有嵌套的二进制文件(比如插件里的native库、内置JRE)
2. tycho-codesign-plugin(Tycho生态专属)
这是Tycho官方生态里专门为Eclipse RCP应用设计的签名插件,能更好地适配Tycho的构建生命周期,自动识别产品路径,无需手动指定复杂参数。
配置示例:
<plugin> <groupId>org.eclipse.tycho</groupId> <artifactId>tycho-codesign-plugin</artifactId> <version>2.7.5</version> <!-- 用和你Tycho版本匹配的最新版 --> <executions> <execution> <id>codesign</id> <phase>verify</phase> <goals> <goal>sign</goal> </goals> <configuration> <signingIdentity>你的开发者签名身份</signingIdentity> <!-- 如果需要权限文件,添加下面的配置 --> <!-- <entitlementsFile>src/main/resources/entitlements.plist</entitlementsFile> --> </configuration> </execution> </executions> </plugin>
额外注意事项
- 构建环境必须配置好有效的Apple开发者证书,且钥匙串能被构建进程访问(如果是CI环境,可能需要提前执行
security unlock-keychain命令解锁钥匙串,同样可以用maven-exec-plugin完成) - 签名完成后再执行打包步骤,确保压缩包内的.app是完整签名状态,避免解压后签名导致的产品损坏问题
内容的提问来源于stack exchange,提问作者fjord
相关产品推荐
相关产品推荐

