docs/main/administration-guide/manage/code-signing-custom-builds.mdx
import Tabs from '@theme/Tabs'; import TabItem from '@theme/TabItem';
<PlanAvailability slug="all-commercial" />Code signing is an essential process for ensuring the authenticity and integrity of your custom Mattermost builds. This guide provides steps on how to code sign a build using your own certificates for Windows, Mac, and Linux.
Make sure to follow each operating system's guidelines and best practices for signing applications.
Install SignTool: Install the Windows SDK to access the SignTool utility.
Obtain a Code Signing Certificate: Purchase or create a certificate (.pfx file) via a CA.
Import the Certificate: Open the .pfx file and import it into the Windows Certificate Store.
Sign the Executable
SignTool to sign your executable:signtool sign /v /s "My" /sha1 <cert hash> /fd SHA256 /tr http://timestamp.digicert.com /td SHA256 <path-to-your-executable>
Create or Import Your GPG Key: If you don't have a GPG key, create one:
gpg --full-generate-key
Alternatively, import an existing GPG key, if you have one:
gpg --import /path/to/your-key.asc
Sign the Package: Use dpkg-sig to sign a Debian package:
dpkg-sig --sign builder your-package.deb
Use rpmsign to sign an RPM package:
rpmsign --addsign your-package.rpm
Verify the Signature: Verify the signature of a .deb package:
dpkg-sig --verify your-package.deb
Verify the signature of an .rpm package:
rpm --checksig your-package.rpm
Obtain a Code Signing Certificate: Create a Developer ID Application certificate in your Apple Developer account and download it.
Import the Certificate: Double-click the certificate to import it into the Keychain.
Sign the Application: Use the codesign tool from Xcode to sign your application:
codesign --deep --force --verify --verbose --sign "Developer ID Application: Your Name (TeamID)" /path/to/your.app
[Optional] Verify the Signature: Verify the signature to ensure everything is correctly signed:
spctl --assess --verbose=4 /path/to/your.app
codesign -dv --verbose=4 /path/to/your.app
SignTool from the Windows SDK with your imported code signing certificate.codesign and spctl tools from Xcode with your Apple Developer ID certificate.GnuPG to create/sign with your GPG key, dpkg-sig for .deb packages, and rpmsign for .rpm packages.