InnoSetup使用GlobalSign EV USB令牌代码签名失败求助
I’ve run into this exact headache with GlobalSign EV tokens before—they work flawlessly for manual signing, but automated tools like InnoSetup tend to trip over their hardware-protected storage. Here’s how I got it working:
First, Grab Your Certificate’s Thumbprint
EV tokens store certificates in a locked-down hardware store, so you need to tell signtool exactly which one to target. To get the thumbprint:
- Open the Certificate Manager (press Win+R, type
mmc, then go to File > Add/Remove Snap-in > Certificates > Add > My user account > Finish > OK). - Navigate to Personal > Certificates, find your GlobalSign EV certificate.
- Right-click it > Properties > Details tab > Scroll down to Thumbprint, copy the entire string (make sure to strip out any spaces between characters).
Update Your InnoSetup [Setup] Section
The default SignTool=signtool is too vague for EV tokens. Replace it with a command that explicitly targets your certificate and handles the hardware token correctly:
[Setup] SignTool=signtool sign /s MY /sha1 YOUR_CERT_THUMBPRINT_HERE /t http://timestamp.globalsign.com/scripts/timstamp.dll /v
Let’s break down these parameters:
/s MY: Tellssigntoolto look in your current user’s Personal certificate store (where the EV token’s certificate is registered)./sha1 YOUR_CERT_THUMBPRINT_HERE: Eliminates ambiguity by pointing directly to your certificate—this is the key fix for repeated prompts./t ...: Uses GlobalSign’s official timestamp server (critical for EV certificates to stay valid long after their issue date)./v: Enables verbose output to help debug if issues persist.
Additional Troubleshooting Tips
If you still get looping prompts:
- Upgrade InnoSetup: Versions older than 6.x have spotty support for hardware security tokens—grab the latest release to avoid compatibility gaps.
- Verify Signtool Version: Make sure you’re using the latest
signtoolfrom the Windows SDK (not an outdated copy from an old Visual Studio install). Runsigntool /?in Command Prompt to confirm it supports smart card parameters. - Run InnoSetup as Admin: Even if manual signing works without elevation, token access sometimes requires administrative privileges for automated tools.
- Enable Debug Logging: Add
/debugto thesigntoolcommand to get detailed error logs. Look for lines about certificate retrieval or token communication failures—this will pinpoint exactly where the process is stuck.
EV tokens are designed to require physical interaction (like entering your PIN) on first use, but repeated prompts almost always mean signtool can’t reliably locate the certificate without explicit parameters.
内容的提问来源于stack exchange,提问作者user285594

