Developer ID签名macOS应用MSAL登录的密钥链组配置问题
解决Developer ID签名macOS应用的MSAL密钥链访问组配置问题
核心结论
Developer ID签名的macOS应用完全可以配置MSAL要求的密钥链访问组,问题出在配置细节不符合Apple的Developer ID签名规则,以下是具体解决步骤:
1. 修正Entitlements文件配置
Apple要求Developer ID签名应用的密钥链访问组必须以你的Team ID作为前缀(而非App Store签名的App特定前缀),修改你的.entitlements文件:
<key>keychain-access-groups</key> <array> <string>$(TeamIdentifierPrefix)com.company.app.bundle.id</string> <string>$(TeamIdentifierPrefix)com.microsoft.identity.universalstorage</string> </array>
- 注意:用
$(TeamIdentifierPrefix)替代原配置中的$(AppIdentifierPrefix)——前者在Developer ID签名场景下会被Xcode替换为你的公司Team ID(形如ABCDE12345.),符合Apple的密钥链组命名规则。
2. 确保签名流程正确嵌入Entitlements
- 在Xcode的Build Settings中,找到
Code Signing Entitlements选项,指定你的entitlements文件路径(比如$(PROJECT_DIR)/YourApp/YourApp.entitlements)。 - 归档并签名后,用以下命令验证应用是否正确包含密钥链组配置:
codesign -d --entitlements - /Applications/YourApp.app
输出结果中应能看到你配置的两个keychain-access-groups条目。
3. 适配MSAL客户端配置
在初始化MSALPublicClientApplication时,确保keychainSharingGroup参数与entitlements中的微软组一致:
MSALPublicClientApplicationConfig *config = [[MSALPublicClientApplicationConfig alloc] initWithClientId:@"YOUR_CLIENT_ID" redirectUri:@"YOUR_REDIRECT_URI" authority:@"YOUR_AUTHORITY"]; config.keychainSharingGroup = [NSString stringWithFormat:@"%@com.microsoft.identity.universalstorage", [[NSBundle mainBundle] objectForInfoDictionaryKey:@"TeamIdentifierPrefix"]]; NSError *error = nil; MSALPublicClientApplication *application = [[MSALPublicClientApplication alloc] initWithConfiguration:config error:&error];
4. 清理旧密钥链条目(可选)
如果之前开发构建的密钥链条目存在权限冲突,打开Keychain Access,搜索com.microsoft.identity.universalstorage和你的应用bundle ID相关条目,删除后重新测试登录流程。
内容的提问来源于stack exchange,提问作者thorax
相关产品推荐
相关产品推荐

