I'm not sure that's right... We use the provided cert/key from Infra directly. No per-sign fee.
> On Sep 10, 2026, at 1:52 PM, [email protected] wrote: > > > Am 10.09.2026 um 19:36 schrieb Jim Jagielski: >> How can that be? Apple signing doesn't use a service afaik. > > Apple hides it as usual. As much as i understand the process is that Xcode > downloads a cert chain from apple developer. > > And uses that cert to sign the binaries. All happens local. you find some > explanations in our build script. > > https://github.com/apache/openoffice/blob/trunk/main/solenv/bin/macosx-codesign.sh > > I just have a high level understanding at the moment. did not have the time > to deepdive. > > If you need more info look in the orig pushed branch: HEAD~2 there you see a > .agent folder. > In that folder should be a long detailed documentation about both topics from > the branch. > On bazel i usually request that the documentation is stored in the module, > but i dont do that on trunk. > > Since normally i work on bazel since it is cheaper for the AI there. I just > dont have bazel for mac yet. > >> >>> On Sep 10, 2026, at 1:33 PM, [email protected] wrote: >>> >>> >>> Am 10.09.2026 um 16:32 schrieb Jim Jagielski: >>>> I believe that is just w/ Windows signing, and not Apple. >>> That was true but even that changed when we switched the service. >>> >>> I need to experiment a bit around. I would like to keep the signing as part >>> of the build. >>> >>> But maybe add it as Flag. Not sure, what is best. cool would be if you >>> could reference the key to use with -signkey="key name" >>> If the Flag is not given the package is not signed. Maybe that could be >>> nice for all build targets. Independant if windows, Linux or Mac. >>> In case of Linux would be maybe nice for flatpack or snap. >>> >>>>> On Sep 10, 2026, at 10:15 AM, Dave Fisher <[email protected] >>>>> <mailto:[email protected]>> wrote: >>>>> >>>>> Unless things have changed signing with ASF credentials is not free. If >>>>> continuing with Peter’s plan then a distinction needs to be made between >>>>> signing a developer’s or ci build, and signing a release build. >>>>> >>>>>> On Sep 10, 2026, at 4:24 AM, Jim Jagielski <[email protected] >>>>>> <mailto:[email protected]> <mailto:[email protected]>> wrote: >>>>>> >>>>>> Whatever you want. I'm done. >>>>>> >>>>>>> On Sep 10, 2026, at 6:54 AM, Peter Kovacs <[email protected] >>>>>>> <mailto:[email protected]> <mailto:[email protected]>> wrote: >>>>>>> >>>>>>> >>>>>>> >>>>>>> Am 10. September 2026 12:24:19 MESZ schrieb Jim Jagielski >>>>>>> <[email protected] <mailto:[email protected]> <mailto:[email protected]> >>>>>>> <mailto:[email protected]>>: >>>>>>>> On our builds, yes of course. But we should not force someone who >>>>>>>> downloads the source and builds for themselves to also sign that. >>>>>>>> >>>>>>>> Traditionally, we've always signed after we build as a separate >>>>>>>> process from building the community build DMGs. >>>>>>>> >>>>>>>> Hopefully that's a bit more clear :) >>>>>>> Ok. And what solution do you propose? >>>>>>> Apple says packaging involves signing. You can not change that. >>>>>>> I am for we release proper signed software or none at all. There is no >>>>>>> in between anymore. >>>>>>>>> On Sep 10, 2026, at 5:59 AM, Peter Kovacs <[email protected] >>>>>>>>> <mailto:[email protected]> <mailto:[email protected]>> >>>>>>>>> wrote: >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> Am 10. September 2026 11:47:21 MESZ schrieb Jim Jagielski >>>>>>>>> <[email protected] <mailto:[email protected]> >>>>>>>>> <mailto:[email protected]>>: >>>>>>>>>> I can't imagine the regular user wanting/needing to sign... >>>>>>>>> Sorry maybe I was not clear. >>>>>>>>> I think we should enforce signing on all builds. >>>>>>>>> The user can always see if that build is from us or someone else. >>>>>>>>> Development builds will always trigger the gatekeeper. >>>>>>>>>>> On Sep 10, 2026, at 5:38 AM, Peter Kovacs <[email protected] >>>>>>>>>>> <mailto:[email protected]> <mailto:[email protected]>> >>>>>>>>>>> wrote: >>>>>>>>>>> >>>>>>>>>>> >>>>>>>>>>> >>>>>>>>>>> Am 10. September 2026 11:30:18 MESZ schrieb Jim Jagielski >>>>>>>>>>> <[email protected] <mailto:[email protected]> >>>>>>>>>>> <mailto:[email protected]> <mailto:[email protected]>>: >>>>>>>>>>>> I am also wondering if the actual signing script itself should be >>>>>>>>>>>> in devtools, somewhere under release-scripts instead. >>>>>>>>>>> The process ist to sign the app, then package the image, and then >>>>>>>>>>> you need to sign again. >>>>>>>>>>> >>>>>>>>>>> I would rather enforce signing to be mandatory. >>>>>>>>>>> What we could put into Devtools maybe is the notarize of the >>>>>>>>>>> installer. Which publishes the release at Apple. I guess. And then >>>>>>>>>>> we could think about a process to publish in the store. >>>>>>>>>>>> Cool work. >>>>>>>>>>> Yes. I hope this will >>>>>>>>>>>>> On Sep 10, 2026, at 5:14 AM, Jim Jagielski <[email protected] >>>>>>>>>>>>> <mailto:[email protected]> <mailto:[email protected]>> wrote: >>>>>>>>>>>>> >>>>>>>>>>>>> Is there any way you could pull out just the signing bits into a >>>>>>>>>>>>> separate commit? >>>>>>>>>>>>> >>>>>>>>>>>>>> On Sep 10, 2026, at 12:26 AM, [email protected] >>>>>>>>>>>>>> <mailto:[email protected]> <mailto:[email protected]> wrote: >>>>>>>>>>>>>> >>>>>>>>>>>>>> >>>>>>>>>>>> -- >>>>>>>>>>>> Jim >>>>>>>>>>>> "This is an outrage!" >>>>>>>>>>>> Tony Harrison >>>>>>>>>>>> >>>>>>>>>>> --------------------------------------------------------------------- >>>>>>>>>>> To unsubscribe, e-mail: [email protected] >>>>>>>>>>> <mailto:[email protected]> >>>>>>>>>>> <mailto:[email protected]> >>>>>>>>>>> <mailto:[email protected]> >>>>>>>>>>> For additional commands, e-mail: [email protected] >>>>>>>>>>> <mailto:[email protected]> >>>>>>>>>>> <mailto:[email protected]> >>>>>>>>>>> <mailto:[email protected]> >>>>>>>>>> -- >>>>>>>>>> Jim >>>>>>>>>> "This is an outrage!" >>>>>>>>>> Tony Harrison >>>>>>>>>> >>>>>>>>> --------------------------------------------------------------------- >>>>>>>>> To unsubscribe, e-mail: [email protected] >>>>>>>>> For additional commands, e-mail: [email protected] >>>>>>>>> >>>>>>>> -- >>>>>>>> Jim >>>>>>>> "This is an outrage!" >>>>>>>> Tony Harrison >>>>>>>> >>>>>>> --------------------------------------------------------------------- >>>>>>> To unsubscribe, e-mail: [email protected] >>>>>>> <mailto:[email protected]> >>>>>>> <mailto:[email protected]> >>>>>>> <mailto:[email protected]> >>>>>>> For additional commands, e-mail: [email protected] >>>>>>> <mailto:[email protected]> >>>>>>> <mailto:[email protected]> >>>>>>> <mailto:[email protected]> >>>>>> -- >>>>>> Jim >>>>>> "This is an outrage!" >>>>>> Tony Harrison >>>>>> >>>>> --------------------------------------------------------------------- >>>>> To unsubscribe, e-mail: [email protected] >>>>> <mailto:[email protected]> >>>>> <mailto:[email protected]> >>>>> For additional commands, e-mail: [email protected] >>>>> <mailto:[email protected]> >>>>> <mailto:[email protected]> >>>> -- >>>> Jim >>>> "This is an outrage!" >>>> Tony Harrison >>>> >>>> >>> --------------------------------------------------------------------- >>> To unsubscribe, e-mail: [email protected] >>> <mailto:[email protected]> >>> For additional commands, e-mail: [email protected] >>> <mailto:[email protected]> >> -- >> Jim >> "This is an outrage!" >> Tony Harrison >> >> > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > <mailto:[email protected]> > For additional commands, e-mail: [email protected] > <mailto:[email protected]> -- Jim "This is an outrage!" Tony Harrison
