Repository navigation
v0.308.203
·
99 commits
to trunk
since this release
Use Apple codesign instead of rcodesign for Fulcio signing
rcodesign re-encodes certificate DER bytes when embedding them in the
CMS signature blob, which silently invalidates the certificate chain
signatures. This causes macOS to report Authority=(unavailable) and
TCC to silently deny mic/camera permissions for hardened-runtime
binaries.
Switch to Apple's native codesign via a temporary keychain:
- Import the Fulcio ephemeral cert+key as PKCS#12
- Create a temporary keychain for the signing operation
- Sign with codesign --options runtime + entitlements
- Clean up the temporary keychain
Apple's codesign preserves the original cert DER encoding, so macOS
resolves the full Authority chain (leaf -> intermediate -> root) and
TCC works correctly with hardened runtime + audio-input entitlement.
Co-Authored-By: Claude Opus 4.6 (1M context) noreply@anthropic.com