如何使用javafxpackager签名MSI?含JavaFX-Gradle-Plugin场景
javafxpackager (and JavaFX-Gradle-Plugin) Great question! I’ve run into this exact gap in the official docs before—they lean heavily into Mac-specific signing options, but the Windows MSI signing workflow with javafxpackager is totally doable. It just relies on Windows’ built-in signtool.exe under the hood, so let’s break this down for both pure javafxpackager and the Gradle plugin.
Pure javafxpackager Approach
First, a quick context check: javafxpackager doesn’t handle signing itself on Windows—it delegates to Microsoft’s signtool.exe (part of the Windows SDK). So you’ll need two prerequisites:
- A valid code signing certificate (in PFX/P12 format; SSL certificates won’t work for code signing)
signtool.exeeither in your system PATH, or you’ll need to specify its full path in your command.
Key Command-Line Parameters
Even though the docs don’t explicitly call out MSI, these universal signing flags work perfectly for Windows native packages:
-sign: Enables signing for the native installer-keyStore: Path to your PFX/P12 certificate file-keyStoreType: Set topkcs12(standard for PFX files)-keyStorePassword: Password for your certificate file-alias: The alias of the certificate in the keystore (usekeytool -list -v -keystore your-cert.pfxto check if you’re unsure)-signtoolPath: Optional, but required ifsigntool.exeisn’t in your PATH (e.g.,C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\signtool.exe—adjust the SDK version to match your setup)
Full Command Example
First package your app JAR, then build and sign the MSI:
# Step 1: Create your application JAR javafxpackager -createjar -appclass com.yourcompany.YourMainApp -srcdir ./dist -outdir ./build -outfile YourApp.jar # Step 2: Build and sign the MSI installer javafxpackager -deploy -native msi -srcdir ./build -outdir ./installer -outfile YourApp -appclass com.yourcompany.YourMainApp ^ -sign ^ -keyStore ./your-code-signing-cert.pfx ^ -keyStoreType pkcs12 ^ -keyStorePassword "your-cert-password" ^ -alias "your-cert-alias" ^ -signtoolPath "C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\signtool.exe"
Verify the Signature
After building, confirm the MSI is signed correctly with:
signtool verify /pa ./installer/YourApp.msi
JavaFX-Gradle-Plugin Approach
If you’re using the plugin, map the same parameters to your Gradle config. Here’s a sample setup for build.gradle:
plugins { id 'java' id 'org.openjfx.javafxplugin' version '0.0.13' } javafx { version = '17' // Use your project's JavaFX version modules = ['javafx.controls', 'javafx.fxml'] // Add your required modules } javafx { deploy { nativeReleaseVersion = '1.0.0' installerType = 'msi' // Target MSI format sign { enabled = true keyStore = file('./your-code-signing-cert.pfx') keyStoreType = 'pkcs12' keyStorePassword = 'your-cert-password' alias = 'your-cert-alias' // Optional: Specify signtool path if it's not in your system PATH signToolPath = 'C:/Program Files (x86)/Windows Kits/10/bin/10.0.19041.0/x64/signtool.exe' } } }
Run the deploy task to build and sign the MSI:
./gradlew jfxNative
Important Notes
- For Java 9+,
javafxpackagerwas renamed tojavapackager—the parameters are identical, just update the command name. - Ensure your code signing certificate is trusted by Windows (either from a commercial CA like DigiCert, or an internal CA if this is for internal use only).
- If your certificate uses a separate key password (different from the keystore password), use the
-keyPassflag injavafxpackagerorkeyPasswordin the Gradle plugin.
内容的提问来源于stack exchange,提问作者Pablo Fernandez

