Repository navigation
v0.309.204
·
98 commits
to trunk
since this release
Use Fulcio CSR path and fix codesign keychain import
Switch from publicKeyRequest to certificateSigningRequest in the
Fulcio v2 API. The CSR is PEM-encoded and base64-wrapped for JSON.
Also fix the PKCS#12 -legacy flag (fallback for older openssl).
Fulcio ignores the CSR subject (always issues empty-subject certs),
but the keychain import + codesign-by-hash approach works: macOS
can read the signing identity from the CMS blob even with an empty
subject, and TCC correctly prompts for mic permission.
Co-Authored-By: Claude Opus 4.6 (1M context) noreply@anthropic.com