# Checking Codesign Signature In-App code

**URL:** <https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424>\
**Category:** macOS\
**Created:** [November 19, 2014, 6:07pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424 "2014-11-19T18:07:35Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 6:07pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/1 "2014-11-19T18:07:35Z")

</div>

One of the advantages of Code signing your app is it also protects your app from being patched (read: cracked - well sort off).  
So when it is patched, the Codesign signature is broken and your app will not launch anymore.

However, lately there seems to be a way to bypass this so an app that has a broken signature, still can be launched without any warning.  
Therefore I wrote a small method to test the codesign signature from within your app.  
You can call this method at random (with for example a timer to trigger it) and see if the codesign signature is broken or not. If yes, you can do whatever you want : quit the app, remove the license, delete the users harddisk (that would teach them but not advised 😉

```auto
Function checkCodesignSignature() As boolean
  dim checkShell as new Shell
  checkShell.execute ("codesign -v "+App.ExecutableFile.parent.parent.parent.ShellPath)
  do
  loop until not checkShell.isrunning
  if instr(checkShell.readAll,"invalid signature") <> 0 then return false
  return true
End Function
```

---

<div class="post-metadata">

**Author:** ![jim\_mckay](https://forum.xojo.com/user_avatar/forum.xojo.com/jim_mckay/32/905_2.png) [@jim\_mckay](https://forum.xojo.com/u/jim_mckay)\
**Post date:** [November 19, 2014, 6:59pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/2 "2014-11-19T18:59:46Z")

</div>

I wouldn’t do that… No guarantee the end user has the codesign command (it’s installed with XCode I believe) and it would be trivial to swap it out with an executable that does nothing, and returns an empty string. There is a method using declares and MBS has functions in the plugins to do this properly…

---

<div class="post-metadata">

**Author:** ![Christian\_Schmitz](https://forum.xojo.com/user_avatar/forum.xojo.com/christian_schmitz/32/158_2.png) [@Christian\_Schmitz](https://forum.xojo.com/u/Christian_Schmitz)\
**Post date:** [November 19, 2014, 7:11pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/3 "2014-11-19T19:11:17Z")

</div>

are you sure codesign is not there always?

and I would also check with “spctl” tool if GateKeeper accepts it.

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 7:33pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/4 "2014-11-19T19:33:46Z")

</div>

> [@144464:@jim mckay](#):
>
> I wouldn’t do that… No guarantee the end user has the codesign command (it’s installed with XCode I believe) and it would be trivial to swap it out with an executable that does nothing, and returns an empty string. There is a method using declares and MBS has functions in the plugins to do this properly…

Every OS X 10.7 and higher has codesign available. Even if Xcode is not installed.  
If it returns a empty string, it will do nothing. Only when the string returned has ‘invalid signature’ it return false.

Works fine for sure.

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 7:35pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/5 "2014-11-19T19:35:11Z")

</div>

> [@144464:@jim mckay](#):
>
> There is a method using declares and MBS has functions in the plugins to do this properly…

Which? Couldn’t find this.

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 7:39pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/6 "2014-11-19T19:39:21Z")

</div>

This is what you get if the app was patched:

/Users/Xtophe/Desktop/test.app: invalid signature (code or signature have been modified)  
In architecture: i386

If it is not patched it just return an empty string.

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 7:40pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/7 "2014-11-19T19:40:16Z")

</div>

> [@144467:@Christian Schmitz](#):
>
> are you sure codesign is not there always?

Yes it is from OSX10.7 and upwards.

---

<div class="post-metadata">

**Author:** ![jim\_mckay](https://forum.xojo.com/user_avatar/forum.xojo.com/jim_mckay/32/905_2.png) [@jim\_mckay](https://forum.xojo.com/u/jim_mckay)\
**Post date:** [November 19, 2014, 8:00pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/8 "2014-11-19T20:00:26Z")

</div>

Oh, you’re right… not sure what I was thinking of. I would recommend using declares though, just seems more secure. And since I mentioned it, here’s a function to check for a valid sgnature.

[code]Function amSigned() As Boolean  
Declare Function SecCodeCopySelf Lib “Security” (flags as integer, byref proc as ptr) As Integer  
Declare Function SecCodeCheckValidity Lib “Security” (code as ptr, flags as integer, requirement as ptr) As Integer

dim myProc as ptr  
dim res As integer

res=SecCodeCopySelf(0,myProc) //get a code object for the current process  
res=res+SecCodeCheckValidity(myProc,0,nil)

if res\<\>0 then Return false //error or failure… in either case, we failed!

return true  
End Function  
[/code]

There’s also more you can do to add a requirement to check for your signature rather than just any valid signature…

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 8:20pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/9 "2014-11-19T20:20:47Z")

</div>

> [@144478:@jim mckay](#):
>
> There’s also more you can do to add a requirement to check for your signature rather than just any valid signature…

True, but checking the validation inapp is good enough to keep your app not being patched (without knowing it).

---

<div class="post-metadata">

**Author:** ![jim\_mckay](https://forum.xojo.com/user_avatar/forum.xojo.com/jim_mckay/32/905_2.png) [@jim\_mckay](https://forum.xojo.com/u/jim_mckay)\
**Post date:** [November 19, 2014, 8:48pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/10 "2014-11-19T20:48:42Z")

</div>

My concern would be that if someone were to patch your app, I think they could just sign it with a different signature afterwards causing validation to pass. Hence the need to verify that it is the correct (original) signature.

---

<div class="post-metadata">

**Author:** ![Norman\_P](https://forum.xojo.com/letter_avatar_proxy/v4/letter/n/858c86/32.png) [@Norman\_P](https://forum.xojo.com/u/Norman_P)\
**Post date:** [November 19, 2014, 9:02pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/11 "2014-11-19T21:02:16Z")

</div>

Certainly could strip the original signature, patch it , sign it voila !  
Signed & hacked 🙂

---

<div class="post-metadata">

**Author:** ![jim\_mckay](https://forum.xojo.com/user_avatar/forum.xojo.com/jim_mckay/32/905_2.png) [@jim\_mckay](https://forum.xojo.com/u/jim_mckay)\
**Post date:** [November 19, 2014, 9:12pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/12 "2014-11-19T21:12:05Z")

</div>

BUT, if you’re signing with an Apple issued certificate, you could check that the root is Apple and the cert is your certificate. I don’t think it’s reasonably possible to get an app signed with a forged Apple cert on a Mac to launch without hacking the OS itself and at that point, forget it. (I could be wrong…)

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 9:23pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/13 "2014-11-19T21:23:24Z")

</div>

> [@144492:@jim mckay](#):
>
> My concern would be that if someone were to patch your app, I think they could just sign it with a different signature afterwards causing validation to pass. Hence the need to verify that it is the correct (original) signature.

And how to verify it is urge correct, original signature?

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 9:24pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/14 "2014-11-19T21:24:28Z")

</div>

[quote=144496:@Norman Palardy]Certainly could strip the original signature, patch it , sign it voila !  
Signed & hacked[/quote]

In that case you could send Apple a mail your apps has been cracked and re-codesigned with another signature. Maybe Apple blocks that signature for future use?

---

<div class="post-metadata">

**Author:** ![jim\_mckay](https://forum.xojo.com/user_avatar/forum.xojo.com/jim_mckay/32/905_2.png) [@jim\_mckay](https://forum.xojo.com/u/jim_mckay)\
**Post date:** [November 19, 2014, 9:27pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/15 "2014-11-19T21:27:05Z")

</div>

Right, and if it was a certificate issued by Apple, I think they could be legally required to provide the owner’s info if there were criminal charges involved.

---

<div class="post-metadata">

**Author:** ![ChristopheDV](https://forum.xojo.com/letter_avatar_proxy/v4/letter/c/59ef9b/32.png) [@ChristopheDV](https://forum.xojo.com/u/ChristopheDV)\
**Post date:** [November 19, 2014, 9:30pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/16 "2014-11-19T21:30:59Z")

</div>

Interesting. 🙂

BTW I ones seriously thought about putting some ‘delete hdd’ code so the cracker that tries the patched app himself, will be in for a big surprise. In the end he will be the first to try it out and for sure will not try it again with the same app. 🙂  
Very tempting though … but … 🙂

---

<div class="post-metadata">

**Author:** ![jim\_mckay](https://forum.xojo.com/user_avatar/forum.xojo.com/jim_mckay/32/905_2.png) [@jim\_mckay](https://forum.xojo.com/u/jim_mckay)\
**Post date:** [November 19, 2014, 9:34pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/17 "2014-11-19T21:34:24Z")

</div>

This should work for adding a requirement to the check.

[code]Function amSigned(requirement As String) As Boolean  
Declare Function SecCodeCopySelf Lib “Security” (flags as integer, byref proc as ptr) As Integer  
Declare Function SecCodeCheckValidity Lib “Security” (code as ptr, flags as integer, requirement as ptr) As Integer  
Declare Function SecRequirementCreateWithString Lib “Security” (text as cfstringref, flags as integer, byref requirement as ptr) As Integer

dim myProc as ptr  
dim res As integer  
dim req As ptr

res=SecCodeCopySelf(0,myProc) //get a code object for the current process  
res=res+SecRequirementCreateWithString(requirement,0,req) //create a code requirement  
res=res+SecCodeCheckValidity(myProc,0,req) //check the validity with a requirement

if res\<\>0 then Return false //error or failure… in either case, we failed!

return true  
End Function  
[/code]

The [requirement language](https://developer.apple.com/library/mac/documentation/Security/Conceptual/CodeSigningGuide/RequirementLang/RequirementLang.html#//apple_ref/doc/uid/TP40005929-CH5-SW1) is a chore to figure out, but…

entitlement["“com.apple.security.app-sandbox”"] exists

will check that the signature includes a sandbox requirement.

---

<div class="post-metadata">

**Author:** ![Tim\_Parnell](https://forum.xojo.com/user_avatar/forum.xojo.com/tim_parnell/32/161_2.png) [@Tim\_Parnell](https://forum.xojo.com/u/Tim_Parnell)\
**Post date:** [November 19, 2014, 10:34pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/18 "2014-11-19T22:34:00Z")

</div>

If you’re going to go through all the trouble to validate the signature is yours they’re just going to skip trying to fake it and modify the subroutine to return true always.  
Hacked + Patched with no checking.

Anything more than stopping casual piracy is a waste of your and your legitimate customers time and resources.

---

<div class="post-metadata">

**Author:** ![jim\_mckay](https://forum.xojo.com/user_avatar/forum.xojo.com/jim_mckay/32/905_2.png) [@jim\_mckay](https://forum.xojo.com/u/jim_mckay)\
**Post date:** [November 19, 2014, 11:09pm UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/19 "2014-11-19T23:09:56Z")

</div>

It’s true that if a hacker wants to crack your app, they will. But I don’t see anything wrong with at least making it difficult. Change the method name and put it in various places and check it from various places. There’s a million apps to hack and getting put on the back burner is really the goal.

---

<div class="post-metadata">

**Author:** ![Sam\_Rowlands](https://forum.xojo.com/user_avatar/forum.xojo.com/sam_rowlands/32/265_2.png) [@Sam\_Rowlands](https://forum.xojo.com/u/Sam_Rowlands)\
**Post date:** [November 20, 2014, 5:35am UTC](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424/20 "2014-11-20T05:35:40Z")

</div>

[quote=144511:@Christoph De Vocht]Interesting. 🙂

BTW I ones seriously thought about putting some ‘delete hdd’ code so the cracker that tries the patched app himself, will be in for a big surprise. In the end he will be the first to try it out and for sure will not try it again with the same app. 🙂  
Very tempting though … but … :)[/quote]  
I know how you feel, but you gotta be real careful with stuff like this, in case some casual user runs a cleanup app or some other tool without realizing that it breaks the code signature and boom… They’ve wiped their drive.

I had once case where a customer was using a tool to clean his drive and it broke the code signature on my application… It took him and I a while to realize what broke it, I had presumed that he was using a cracked version (because the code signature was broken).

[Next page](https://forum.xojo.com/t/checking-codesign-signature-in-app-code/20424.md?page=2)
