From 3e0db567e89fdc6fde158cfabee650187a34127d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Mislav=20Marohni=C4=87?= Date: Tue, 15 Feb 2022 17:23:39 +0100 Subject: [PATCH] Rotate our Windows signing certificates (#5196) - The certificate pfx file is now read from WINDOWS_CERT_PFX - The password to decode the pfx is in WINDOWS_CERT_PASSWORD - Quit reading from desktop-secrets repo - Switch osslsigncode to take in pfx instead of individual certs - :fire: obsolete setup scripts --- .github/workflows/releases.yml | 21 +++++++++++++------ .goreleaser.yml | 1 - script/prepare-windows-cert.sh | 19 ----------------- script/setup-windows-certificate.ps1 | 12 ----------- script/sign-windows-executable.sh | 31 ++++++++++++++-------------- script/sign.ps1 | 7 +------ 6 files changed, 31 insertions(+), 60 deletions(-) delete mode 100755 script/prepare-windows-cert.sh delete mode 100644 script/setup-windows-certificate.ps1 diff --git a/.github/workflows/releases.yml b/.github/workflows/releases.yml index b95c51715..6511fc71c 100644 --- a/.github/workflows/releases.yml +++ b/.github/workflows/releases.yml @@ -27,6 +27,13 @@ jobs: GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}} - name: Install osslsigncode run: sudo apt-get install -y osslsigncode + - name: Obtain signing cert + run: | + cert="$(mktemp -t cert.XXX)" + base64 -d <<<"$CERT_CONTENTS" > "$cert" + echo "CERT_FILE=$cert" >> $GITHUB_ENV + env: + CERT_CONTENTS: ${{ secrets.WINDOWS_CERT_PFX }} - name: Run GoReleaser uses: goreleaser/goreleaser-action@v2 with: @@ -35,8 +42,7 @@ jobs: env: GITHUB_TOKEN: ${{secrets.GITHUB_TOKEN}} GORELEASER_CURRENT_TAG: ${{steps.changelog.outputs.tag-name}} - GITHUB_CERT_PASSWORD: ${{secrets.GITHUB_CERT_PASSWORD}} - DESKTOP_CERT_TOKEN: ${{secrets.DESKTOP_CERT_TOKEN}} + CERT_PASSWORD: ${{secrets.WINDOWS_CERT_PASSWORD}} - name: Checkout documentation site uses: actions/checkout@v2 with: @@ -147,15 +153,18 @@ jobs: "${MSBUILD_PATH}\MSBuild.exe" ./build/windows/gh.wixproj -p:SourceDir="$PWD" -p:OutputPath="$PWD" -p:OutputName="$name" -p:ProductVersion="$version" - name: Obtain signing cert id: obtain_cert + shell: bash + run: | + base64 -d <<<"$CERT_CONTENTS" > ./cert.pfx + printf "::set-output name=cert-file::%s\n" ".\\cert.pfx" env: - DESKTOP_CERT_TOKEN: ${{ secrets.DESKTOP_CERT_TOKEN }} - run: .\script\setup-windows-certificate.ps1 + CERT_CONTENTS: ${{ secrets.WINDOWS_CERT_PFX }} - name: Sign MSI env: CERT_FILE: ${{ steps.obtain_cert.outputs.cert-file }} EXE_FILE: ${{ steps.buildmsi.outputs.msi }} - GITHUB_CERT_PASSWORD: ${{ secrets.GITHUB_CERT_PASSWORD }} - run: .\script\sign.ps1 -Certificate $env:CERT_FILE -Executable $env:EXE_FILE + CERT_PASSWORD: ${{ secrets.WINDOWS_CERT_PASSWORD }} + run: .\script\signtool sign /d "GitHub CLI" /f $env:CERT_FILE /p $env:CERT_PASSWORD /fd sha256 /tr http://timestamp.digicert.com /v $env:EXE_FILE - name: Upload MSI shell: bash run: | diff --git a/.goreleaser.yml b/.goreleaser.yml index 01c727d93..68d3dd9c9 100644 --- a/.goreleaser.yml +++ b/.goreleaser.yml @@ -9,7 +9,6 @@ before: hooks: - go mod tidy - make manpages GH_VERSION={{.Version}} - - ./script/prepare-windows-cert.sh '{{ if index .Env "GITHUB_CERT_PASSWORD" }}{{ .Env.GITHUB_CERT_PASSWORD}}{{ end }}' '{{ if index .Env "DESKTOP_CERT_TOKEN" }}{{ .Env.DESKTOP_CERT_TOKEN}}{{ end }}' builds: - <<: &build_defaults diff --git a/script/prepare-windows-cert.sh b/script/prepare-windows-cert.sh deleted file mode 100755 index d52d12b1d..000000000 --- a/script/prepare-windows-cert.sh +++ /dev/null @@ -1,19 +0,0 @@ -#!/bin/bash -set -e - -GITHUB_CERT_PASSWORD=$1 -DESKTOP_CERT_TOKEN=$2 - -if [[ -z "$GITHUB_CERT_PASSWORD" || -z "$DESKTOP_CERT_TOKEN" ]]; then - echo "skipping windows signing prep; cert password or token not found" - exit 0 -fi - -curl \ - -H "Authorization: token $DESKTOP_CERT_TOKEN" \ - -H "Accept: application/vnd.github.v3.raw" \ - --output windows-certificate.pfx \ - https://api.github.com/repos/desktop/desktop-secrets/contents/windows-certificate.pfx - -openssl pkcs12 -in windows-certificate.pfx -nocerts -nodes -out private-key.pem -passin pass:${GITHUB_CERT_PASSWORD} -openssl pkcs12 -in windows-certificate.pfx -nokeys -nodes -out certificate.pem -passin pass:${GITHUB_CERT_PASSWORD} diff --git a/script/setup-windows-certificate.ps1 b/script/setup-windows-certificate.ps1 deleted file mode 100644 index 9238fe67b..000000000 --- a/script/setup-windows-certificate.ps1 +++ /dev/null @@ -1,12 +0,0 @@ -$scriptPath = split-path -parent $MyInvocation.MyCommand.Definition -$certFile = "$scriptPath\windows-certificate.pfx" - -$headers = New-Object "System.Collections.Generic.Dictionary[[String],[String]]" -$headers.Add("Authorization", "token $env:DESKTOP_CERT_TOKEN") -$headers.Add("Accept", 'application/vnd.github.v3.raw') - -Invoke-WebRequest 'https://api.github.com/repos/desktop/desktop-secrets/contents/windows-certificate.pfx' ` - -Headers $headers ` - -OutFile "$certFile" - -Write-Output "::set-output name=cert-file::$certFile" diff --git a/script/sign-windows-executable.sh b/script/sign-windows-executable.sh index 2141c9552..d89e6dbe4 100755 --- a/script/sign-windows-executable.sh +++ b/script/sign-windows-executable.sh @@ -1,26 +1,25 @@ #!/bin/bash set -e -if [[ ! -e certificate.pem || ! -e private-key.pem ]]; then - echo "skipping windows signing; cert or key not found" +EXE="$1" + +if [ -z "$CERT_FILE" ]; then + echo "skipping Windows code-signing; CERT_FILE not set" >&2 exit 0 fi -EXECUTABLE_PATH=$1 -ARCH="386" - -if [[ $EXECUTABLE_PATH =~ "amd64" ]]; then - ARCH="amd64" +if [ ! -f "$CERT_FILE" ]; then + echo "error Windows code-signing; file '$CERT_FILE' not found" >&2 + exit 1 fi -OUT_PATH=gh_signed-${ARCH}.exe +if [ -z "$CERT_PASSWORD" ]; then + echo "error Windows code-signing; no value for CERT_PASSWORD" >&2 + exit 1 +fi -osslsigncode sign \ - -certs certificate.pem \ - -key private-key.pem \ - -n "GitHub CLI" \ - -t http://timestamp.digicert.com \ - -in $EXECUTABLE_PATH \ - -out $OUT_PATH +osslsigncode sign -n "GitHub CLI" -t http://timestamp.digicert.com \ + -pkcs12 "$CERT_FILE" -readpass <(printf "%s" "$CERT_PASSWORD") -h sha256 \ + -in "$EXE" -out "$EXE"~ -mv $OUT_PATH $EXECUTABLE_PATH +mv "$EXE"~ "$EXE" diff --git a/script/sign.ps1 b/script/sign.ps1 index ec724f7bd..336e0204c 100644 --- a/script/sign.ps1 +++ b/script/sign.ps1 @@ -6,12 +6,7 @@ param ( Set-StrictMode -Version Latest $ErrorActionPreference = "Stop" -$thumbprint = "fb713a60a7fa79dfc03cb301ca05d4e8c1bdd431" -$passwd = $env:GITHUB_CERT_PASSWORD $ProgramName = "GitHub CLI" - $scriptPath = split-path -parent $MyInvocation.MyCommand.Definition -& $scriptPath\signtool.exe sign /d $ProgramName /f $Certificate /p $passwd ` - /sha1 $thumbprint /fd sha256 /tr http://timestamp.digicert.com /td sha256 /v ` - $Executable +& $scriptPath\signtool.exe sign /d $ProgramName /f $Certificate /p $env:CERT_PASSWORD /fd sha256 /tr http://timestamp.digicert.com /v $Executable