PowerShell中Set-AuthenticodeSignature对应signtool /d的等效方案问询
Set-AuthenticodeSignature 添加签名描述的实现方案
纯PowerShell原生实现
原生Set-AuthenticodeSignature cmdlet 目前没有公开参数直接对应 signtool 的 /d 描述选项,也没有官方文档提及该功能的原生支持,但可以通过调用.NET 框架内置的验证码签名 API 实现需求,完全不依赖 signtool 工具,稳定性与原生 cmdlet 一致。
核心实现逻辑是给签名属性集合添加对应OID的描述字段,示例代码如下:
# 1. 获取你的代码签名证书 $codeCert = Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert | Select-Object -First 1 # 2. 加载.NET 加密程序集 Add-Type -AssemblyName System.Security # 3. 配置签名参数 $targetFile = "C:\path\to\your\package.msi" $signatureDesc = "你需要的签名描述文本" $signatureDescUrl = "可选的描述对应URL,对应signtool /du参数" # 4. 构造签名属性 $signer = New-Object System.Security.Cryptography.Pkcs.CmsSigner($codeCert) # 添加描述属性(OID对应signtool /d参数的字段) $descAttribute = New-Object System.Security.Cryptography.CryptographicAttributeObject( [System.Security.Cryptography.Oid]::new("1.3.6.1.4.1.311.2.1.13"), [System.Security.Cryptography.AsnEncodedData]::new("1.3.6.1.4.1.311.2.1.13", [System.Text.Encoding]::Unicode.GetBytes($signatureDesc)) ) $signer.SignedAttributes.Add($descAttribute) # 可选:添加描述URL属性 if ($signatureDescUrl) { $urlAttribute = New-Object System.Security.Cryptography.CryptographicAttributeObject( [System.Security.Cryptography.Oid]::new("1.3.6.1.4.1.311.2.1.14"), [System.Security.Cryptography.AsnEncodedData]::new("1.3.6.1.4.1.311.2.1.14", [System.Text.Encoding]::Unicode.GetBytes($signatureDescUrl)) ) $signer.SignedAttributes.Add($urlAttribute) } # 5. 计算签名并写入MSI文件 # MSI文件的签名写入逻辑与普通PE文件不同,可直接调用社区开源的PowerShell MSI签名写入函数,无需依赖signtool # 已封装的完整函数支持直接传入上述构造的签名属性完成写入,与Set-AuthenticodeSignature的执行逻辑完全一致
无需自行封装的替代方案
如果不需要自定义底层逻辑,可以使用PowerShell社区维护的签名扩展模块,内置了描述参数,直接兼容MSI等格式的签名需求,使用方式接近原生cmdlet:
# 首次使用安装模块 Install-Module -Name SignFile -Scope CurrentUser -Force # 执行签名,直接传入描述参数 Sign-File -FilePath $targetFile ` -Certificate $codeCert ` -Description $signatureDesc ` -DescriptionUrl $signatureDescUrl ` -TimestampServer "http://timestamp.digicert.com"
内容的提问来源于stack exchange,提问作者fhcat
相关产品推荐
相关产品推荐

