Signing #2004
Replies: 8 comments 2 replies
-
Thank you for your proposal. |
Beta Was this translation helpful? Give feedback.
-
BTW, I have a question about Homebrew. |
Beta Was this translation helpful? Give feedback.
-
yes homebrew compiles and signs it is my understanding. but check it ... |
Beta Was this translation helpful? Give feedback.
-
https://docs.brew.sh/FAQ#why-cant-i-open-a-mac-app-from-an-unidentified-developer its not quite what we want but its all i could find. |
Beta Was this translation helpful? Give feedback.
-
if its not signed it wont run unless the developer has allows it https://support.apple.com/en-us/HT202491 because most devs have this setting for "unidentifed" devs, then home brew apps work. so without turning off security at the Mac OS preferences level the app wont run. hence why signing is needed. Beps code does it btw... Its quote well done |
Beta Was this translation helpful? Give feedback.
-
Hmm. I can't understand why aqua works without trouble. |
Beta Was this translation helpful? Give feedback.
-
And I wonder if it is correct for aqua to sign tools because aqua can't verify if the package is safe. |
Beta Was this translation helpful? Give feedback.
-
Yeah I know what you mean. aqua should NOT be signing on others behalf. It’s all down to Providence . Whi signs and who is the custodian of the signing. Who do you trust… I honestly am stumped because I think different users want different things. Also Apple is the only one that demands signing , really it should by the code authour signing it by putting their keys ( p12) into their CI. If Aqua gets code or s binary from sone git then it should ask the authour to sign it. Like a CI error message. if the authour does not care then delivery the binary through aqua and let the users have a mechanism via Aqua to yell at the authour. Aqua can keep sone data about how many are yelling and so the authour can decide if it’s worth going to the effort of signing . that’s my brain storm on this. apple wants a “ throat to choke” and that’s why it’s signing “ chain of trust” is designed to point back to a real human or company. Dun and Bradstreet is one of the chains of trust apple uses for companies for example. For people it’s their passport or whatever. https://developer.apple.com/support/D-U-N-S/ so suggest that the pushing of gnudges back to the authour is practical solution to the ecosystem that Apple insists on .. |
Beta Was this translation helpful? Give feedback.
-
Overview
Mac pkgs sometimes need to be signed and not all are.
the call is:
They is a way to do this such that the certs do NOT need to be in a Mac Keychain also, which would be needed.
Why is the proposal needed?
to sign pkgs..
Reference
Beta Was this translation helpful? Give feedback.
All reactions