How do I securely configure a CI server to digitally sign binaries?

前端 未结 2 1742
攒了一身酷
攒了一身酷 2020-12-24 13:53

There are many sites that explain how to run signtool.exe on a .pfx certificate file, which boil down to:

signtool.exe sign /f myce         


        
2条回答
  •  太阳男子
    2020-12-24 14:07

    One common technique is to leave keys and certificates in Version Control, but protect them with a password or passphrase. The password is saved in environment variables local to the machine, which can be easily accessed from scripts (e.g. %PASSWORD_FOR_CERTIFICATES%).

    One must be careful not to log these values in plain text.

提交回复
热议问题