You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用javafxpackager签名MSI?含JavaFX-Gradle-Plugin场景

Signing MSI Packages with javafxpackager (and JavaFX-Gradle-Plugin)

Great question! I’ve run into this exact gap in the official docs before—they lean heavily into Mac-specific signing options, but the Windows MSI signing workflow with javafxpackager is totally doable. It just relies on Windows’ built-in signtool.exe under the hood, so let’s break this down for both pure javafxpackager and the Gradle plugin.

Pure javafxpackager Approach

First, a quick context check: javafxpackager doesn’t handle signing itself on Windows—it delegates to Microsoft’s signtool.exe (part of the Windows SDK). So you’ll need two prerequisites:

  • A valid code signing certificate (in PFX/P12 format; SSL certificates won’t work for code signing)
  • signtool.exe either in your system PATH, or you’ll need to specify its full path in your command.

Key Command-Line Parameters

Even though the docs don’t explicitly call out MSI, these universal signing flags work perfectly for Windows native packages:

  • -sign: Enables signing for the native installer
  • -keyStore: Path to your PFX/P12 certificate file
  • -keyStoreType: Set to pkcs12 (standard for PFX files)
  • -keyStorePassword: Password for your certificate file
  • -alias: The alias of the certificate in the keystore (use keytool -list -v -keystore your-cert.pfx to check if you’re unsure)
  • -signtoolPath: Optional, but required if signtool.exe isn’t in your PATH (e.g., C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\signtool.exe—adjust the SDK version to match your setup)

Full Command Example

First package your app JAR, then build and sign the MSI:

# Step 1: Create your application JAR
javafxpackager -createjar -appclass com.yourcompany.YourMainApp -srcdir ./dist -outdir ./build -outfile YourApp.jar

# Step 2: Build and sign the MSI installer
javafxpackager -deploy -native msi -srcdir ./build -outdir ./installer -outfile YourApp -appclass com.yourcompany.YourMainApp ^
  -sign ^
  -keyStore ./your-code-signing-cert.pfx ^
  -keyStoreType pkcs12 ^
  -keyStorePassword "your-cert-password" ^
  -alias "your-cert-alias" ^
  -signtoolPath "C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x64\signtool.exe"

Verify the Signature

After building, confirm the MSI is signed correctly with:

signtool verify /pa ./installer/YourApp.msi

JavaFX-Gradle-Plugin Approach

If you’re using the plugin, map the same parameters to your Gradle config. Here’s a sample setup for build.gradle:

plugins {
    id 'java'
    id 'org.openjfx.javafxplugin' version '0.0.13'
}

javafx {
    version = '17' // Use your project's JavaFX version
    modules = ['javafx.controls', 'javafx.fxml'] // Add your required modules
}

javafx {
    deploy {
        nativeReleaseVersion = '1.0.0'
        installerType = 'msi' // Target MSI format
        sign {
            enabled = true
            keyStore = file('./your-code-signing-cert.pfx')
            keyStoreType = 'pkcs12'
            keyStorePassword = 'your-cert-password'
            alias = 'your-cert-alias'
            // Optional: Specify signtool path if it's not in your system PATH
            signToolPath = 'C:/Program Files (x86)/Windows Kits/10/bin/10.0.19041.0/x64/signtool.exe'
        }
    }
}

Run the deploy task to build and sign the MSI:

./gradlew jfxNative

Important Notes

  • For Java 9+, javafxpackager was renamed to javapackager—the parameters are identical, just update the command name.
  • Ensure your code signing certificate is trusted by Windows (either from a commercial CA like DigiCert, or an internal CA if this is for internal use only).
  • If your certificate uses a separate key password (different from the keystore password), use the -keyPass flag in javafxpackager or keyPassword in the Gradle plugin.

内容的提问来源于stack exchange,提问作者Pablo Fernandez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:36:11