Mac命令行工具分发遇阻:未识别开发者报错求助
Hey there, let's get this sorted out once and for all—no more asking users to fumble through Security & Privacy settings to open your CLI tool. The issue boils down to using the right certificate, proper code signing, and critical Apple notarization steps that you might have missed. Here's a step-by-step breakdown:
1. Use the Correct Certificate First
First off, let's clarify which certificates are meant for what, since you tried a few:
- Mac Developer: Only for testing on devices registered to your Apple Developer team. This won't work for external users (even internal non-team employees) and will trigger the error every time.
- Mac App Distribution: Strictly for submitting apps to the Mac App Store. If you're distributing directly to users (not via the App Store), this certificate is irrelevant.
- Developer ID Application: This is the one you need. It's designed specifically for distributing apps/cli tools outside the App Store to any Mac user.
2. Properly Sign Your CLI Tool
GUI apps get signed automatically during archivation, but CLI tools sometimes need a little extra care. If you're not already manually signing it, run this command (replace placeholders with your details):
codesign --force --sign "Developer ID Application: Your Company Name (YOUR_TEAM_ID)" /path/to/your/cli-tool
- You can find your full certificate name by opening Keychain Access and looking under "My Certificates".
- The
--forceflag ensures any existing (invalid) signatures are overwritten.
3. Notarize Your Tool (Non-Negotiable for macOS 10.14.5+)
Apple now requires all externally distributed Mac software to be notarized—this is the big one that's likely missing from your process. Here's how to do it for a CLI tool:
- Package your tool into a zip: Notarization requires a compressed archive. Use
dittoto ensure it's properly packaged:ditto -c -k --sequesterRsrc --keepParent /path/to/your/cli-tool /path/to/cli-tool.zip - Submit to Apple's notary service: Use
notarytool(replace placeholders with your Apple ID, team ID, and App Store Connect app-specific password—never use your regular Apple ID password here):
Thexcrun notarytool submit /path/to/cli-tool.zip --apple-id "your-apple-id@example.com" --team-id "YOUR_TEAM_ID" --password "your-app-specific-password" --wait--waitflag will keep the command running until notarization completes, so you'll see a success/failure message right away. - Staple the notarization ticket: This attaches the notarization proof directly to your tool, so users don't need an internet connection to verify it:
xcrun stapler staple /path/to/your/cli-tool
4. Verify Everything Worked
Run these commands to confirm your tool is properly signed and notarized:
- Check the signature details:
Look forcodesign -dv --verbose=4 /path/to/your/cli-toolAuthority=Developer ID Application: Your Company...andStapled: Yesin the output. - Check if macOS accepts it:
If you seespctl -a -vvv -t install /path/to/your/cli-toolacceptedat the end, you're good to go.
5. Bonus: Internal Distribution Tips
If you're distributing to internal employees only, you could also use MDM (Mobile Device Management) to push a trust profile for your Developer ID certificate. But notarization is still the best approach—it works for both internal and external users without extra setup on their end.
内容的提问来源于stack exchange,提问作者Alejandro Cotilla

