You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

InnoSetup使用GlobalSign EV USB令牌代码签名失败求助

Fixing InnoSetup Signing Failures with GlobalSign EV USB Token Certificates

I’ve run into this exact headache with GlobalSign EV tokens before—they work flawlessly for manual signing, but automated tools like InnoSetup tend to trip over their hardware-protected storage. Here’s how I got it working:

First, Grab Your Certificate’s Thumbprint

EV tokens store certificates in a locked-down hardware store, so you need to tell signtool exactly which one to target. To get the thumbprint:

  • Open the Certificate Manager (press Win+R, type mmc, then go to File > Add/Remove Snap-in > Certificates > Add > My user account > Finish > OK).
  • Navigate to Personal > Certificates, find your GlobalSign EV certificate.
  • Right-click it > Properties > Details tab > Scroll down to Thumbprint, copy the entire string (make sure to strip out any spaces between characters).

Update Your InnoSetup [Setup] Section

The default SignTool=signtool is too vague for EV tokens. Replace it with a command that explicitly targets your certificate and handles the hardware token correctly:

[Setup]
SignTool=signtool sign /s MY /sha1 YOUR_CERT_THUMBPRINT_HERE /t http://timestamp.globalsign.com/scripts/timstamp.dll /v

Let’s break down these parameters:

  • /s MY: Tells signtool to look in your current user’s Personal certificate store (where the EV token’s certificate is registered).
  • /sha1 YOUR_CERT_THUMBPRINT_HERE: Eliminates ambiguity by pointing directly to your certificate—this is the key fix for repeated prompts.
  • /t ...: Uses GlobalSign’s official timestamp server (critical for EV certificates to stay valid long after their issue date).
  • /v: Enables verbose output to help debug if issues persist.

Additional Troubleshooting Tips

If you still get looping prompts:

  • Upgrade InnoSetup: Versions older than 6.x have spotty support for hardware security tokens—grab the latest release to avoid compatibility gaps.
  • Verify Signtool Version: Make sure you’re using the latest signtool from the Windows SDK (not an outdated copy from an old Visual Studio install). Run signtool /? in Command Prompt to confirm it supports smart card parameters.
  • Run InnoSetup as Admin: Even if manual signing works without elevation, token access sometimes requires administrative privileges for automated tools.
  • Enable Debug Logging: Add /debug to the signtool command to get detailed error logs. Look for lines about certificate retrieval or token communication failures—this will pinpoint exactly where the process is stuck.

EV tokens are designed to require physical interaction (like entering your PIN) on first use, but repeated prompts almost always mean signtool can’t reliably locate the certificate without explicit parameters.

内容的提问来源于stack exchange,提问作者user285594

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 03:40:12