update workflow for 2024 signing

This commit is contained in:
dovholuknf
2024-04-22 21:00:38 -04:00
parent c9d4ffa65a
commit 5934b83ede
2 changed files with 7 additions and 3 deletions
+4
View File
@@ -27,7 +27,9 @@ jobs:
gh_ci_key: ${{ secrets.GH_CI_KEY }}
ZITI_DEBUG: "yes_please"
OPENZITI_P12_PASS: ${{ secrets.OPENZITI_P12_PASS }}
OPENZITI_P12_PASS_2024: ${{ secrets.OPENZITI_P12_PASS_2024 }}
OPENZITI_P12: ${{ secrets.OPENZITI_P12 }}
OPENZITI_P12_2024: ${{ secrets.OPENZITI_P12_2024 }}
steps:
- name: Git Checkout
@@ -45,8 +47,10 @@ jobs:
run: |
echo "${env:SIGNING_CERT}" > WinSign.b64
echo "${env:OPENZITI_P12}" > OPENZITI_P12.b64
echo "${env:OPENZITI_P12_2024}" > OPENZITI_P12_2024.b64
C:\Windows\System32\certutil.exe -decode WinSign.b64 Installer/WinSign.p12
C:\Windows\System32\certutil.exe -decode OPENZITI_P12.b64 Installer/openziti.p12
C:\Windows\System32\certutil.exe -decode OPENZITI_P12_2024.b64 Installer/openziti_2024.p12
- name: Trying to run choco install.
run: Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://chocolatey.org/install.ps1'))
- name: "Install Choco needs: wixtoolset ninja"
+3 -3
View File
@@ -132,14 +132,14 @@ if (Get-Command -Name "jsign.exe" -ErrorAction SilentlyContinue) {
echo ""
}
if($null -eq $env:OPENZITI_P12_PASS) {
if($null -eq $env:OPENZITI_P12_PASS_2024) {
echo ""
echo "Not calling signtool - env:OPENZITI_P12_PASS is not set"
echo "Not calling signtool - env:OPENZITI_P12_PASS_2024 is not set"
echo ""
} else {
echo "adding additional signature to executable with openziti.org signing certificate"\
echo "Using ${ADV_INST_HOME}\third-party\winsdk\x64\signtool to sign the executable with the OpenZiti signing cert"
& "$ADV_INST_HOME\third-party\winsdk\x64\signtool" sign /f "${scriptPath}\openziti.p12" /p "${env:OPENZITI_P12_PASS}" /tr http://ts.ssl.com /fd sha512 /td sha512 /as "${exeAbsPath}"
& "$ADV_INST_HOME\third-party\winsdk\x64\signtool" sign /f "${scriptPath}\openziti_2024.p12" /p "${env:OPENZITI_P12_PASS_2024}" /tr http://ts.ssl.com /fd sha512 /td sha512 /as "${exeAbsPath}"
}
(Get-FileHash "${exeAbsPath}").Hash > "${scriptPath}\Output\Ziti Desktop Edge Client-${installerVersion}.exe.sha256"