# Code signing app

**URL:** <https://forum.xojo.com/t/code-signing-app/76407>\
**Category:** Getting Started\
**Created:** [July 5, 2023, 4:11pm UTC](https://forum.xojo.com/t/code-signing-app/76407 "2023-07-05T16:11:06Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Fatte](https://forum.xojo.com/letter_avatar_proxy/v4/letter/j/4bbf92/32.png) [@John\_Fatte](https://forum.xojo.com/u/John_Fatte)\
**Post date:** [July 5, 2023, 4:11pm UTC](https://forum.xojo.com/t/code-signing-app/76407/1 "2023-07-05T16:11:06Z")

</div>

Is there a way to tell which items inside your DMG are not code signed?

I create the DMG and it installs find in the Applications, but if I upload to our website and download it from there, when I attempt to run the APP, it says it’s damaged.

Also, any good resources that explain how to code sign all the items inside your DMG?

---

<div class="post-metadata">

**Author:** ![Rick\_Araujo](https://forum.xojo.com/user_avatar/forum.xojo.com/rick_araujo/32/251_2.png) [@Rick\_Araujo](https://forum.xojo.com/u/Rick_Araujo)\
**Post date:** [July 5, 2023, 4:30pm UTC](https://forum.xojo.com/t/code-signing-app/76407/2 "2023-07-05T16:30:42Z")

</div>

I would say that using the pair [AppWrapper](https://ohanaware.com/appwrapper/) to proper sign/notarize things, and [DMG Canvas](https://www.araelium.com/dmgcanvas) to sign/notarize your DMG, you should not have such problem.

---

<div class="post-metadata">

**Author:** ![Christian\_Schmitz](https://forum.xojo.com/user_avatar/forum.xojo.com/christian_schmitz/32/158_2.png) [@Christian\_Schmitz](https://forum.xojo.com/u/Christian_Schmitz)\
**Post date:** [July 5, 2023, 4:34pm UTC](https://forum.xojo.com/t/code-signing-app/76407/3 "2023-07-05T16:34:39Z")

</div>

You run a command

`spctl -a -v -t install test.dmg`

with the path to the dmg.  
it should output something like

> test.dmg: accepted  
> source=Notarized Developer ID

---

<div class="post-metadata">

**Author:** ![John\_Fatte](https://forum.xojo.com/letter_avatar_proxy/v4/letter/j/4bbf92/32.png) [@John\_Fatte](https://forum.xojo.com/u/John_Fatte)\
**Post date:** [July 5, 2023, 7:17pm UTC](https://forum.xojo.com/t/code-signing-app/76407/4 "2023-07-05T19:17:05Z")

</div>

> [@Christian\_Schmitz](#):
>
> spctl

It looks like that only will verify that it’s been notarized, but not code signed?

---

<div class="post-metadata">

**Author:** ![Christian\_Schmitz](https://forum.xojo.com/user_avatar/forum.xojo.com/christian_schmitz/32/158_2.png) [@Christian\_Schmitz](https://forum.xojo.com/u/Christian_Schmitz)\
**Post date:** [July 5, 2023, 7:19pm UTC](https://forum.xojo.com/t/code-signing-app/76407/5 "2023-07-05T19:19:47Z")

</div>

if not notarized, but signed, it will show this:

> test.dmg: rejected  
> source=Unnotarized Developer ID

---

<div class="post-metadata">

**Author:** ![John\_Fatte](https://forum.xojo.com/letter_avatar_proxy/v4/letter/j/4bbf92/32.png) [@John\_Fatte](https://forum.xojo.com/u/John_Fatte)\
**Post date:** [July 5, 2023, 7:20pm UTC](https://forum.xojo.com/t/code-signing-app/76407/6 "2023-07-05T19:20:32Z")

</div>

Excellent, we don’t need it notarized, just code signed and that’s the response I got.

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![John\_Fatte](https://forum.xojo.com/letter_avatar_proxy/v4/letter/j/4bbf92/32.png) [@John\_Fatte](https://forum.xojo.com/u/John_Fatte)\
**Post date:** [July 5, 2023, 7:45pm UTC](https://forum.xojo.com/t/code-signing-app/76407/7 "2023-07-05T19:45:54Z")

</div>

Sorry, follow up question. We have code signing in an application that we wrote and it appears to be working correctly; however, just for clarification and because the developer that wrote that app is no longer employed with us, what exactly do you need to code sign in your app?

---

<div class="post-metadata">

**Author:** ![Beatrix\_Willius](https://forum.xojo.com/user_avatar/forum.xojo.com/beatrix_willius/32/282_2.png) [@Beatrix\_Willius](https://forum.xojo.com/u/Beatrix_Willius)\
**Post date:** [July 6, 2023, 6:31am UTC](https://forum.xojo.com/t/code-signing-app/76407/8 "2023-07-06T06:31:41Z")

</div>

Code signing without notarisation doesn’t do anything these days. You still get the dialog “app can contain malicious code”.

You need a developer account, you download the certificates. And then you need to enter the name of the certificate into Xojo and the app you are making the dmg with.

---

<div class="post-metadata">

**Author:** ![Greg\_O](https://forum.xojo.com/user_avatar/forum.xojo.com/greg_o/32/22785_2.png) [@Greg\_O](https://forum.xojo.com/u/Greg_O)\
**Post date:** [July 6, 2023, 11:05am UTC](https://forum.xojo.com/t/code-signing-app/76407/9 "2023-07-06T11:05:16Z")

</div>

> [@John\_Fatte](#):
>
> what exactly do you need to code sign in your app?

You need to sign any binary code inside the app bundle and then sign the whole bundle.

Specifically:

- yourApp.app/Contents/Frameworks/
- yourApp.app/Contents/Helpers/ (if it exists)
- yourApp.app

Even better, get yourself a copy of [AppWrapper](https://ohanaware.com/appwrapper/) and have it do all the relevant parts. It’ll even do the notarization.

---

<div class="post-metadata">

**Author:** ![John\_Fatte](https://forum.xojo.com/letter_avatar_proxy/v4/letter/j/4bbf92/32.png) [@John\_Fatte](https://forum.xojo.com/u/John_Fatte)\
**Post date:** [July 7, 2023, 1:55pm UTC](https://forum.xojo.com/t/code-signing-app/76407/10 "2023-07-07T13:55:56Z")

</div>

Beatrix, you stated “you need to enter the name of the certificate into XOJO and the app you are making”. How do you do that?

---

<div class="post-metadata">

**Author:** ![Beatrix\_Willius](https://forum.xojo.com/user_avatar/forum.xojo.com/beatrix_willius/32/282_2.png) [@Beatrix\_Willius](https://forum.xojo.com/u/Beatrix_Willius)\
**Post date:** [July 7, 2023, 2:14pm UTC](https://forum.xojo.com/t/code-signing-app/76407/11 "2023-07-07T14:14:39Z")

</div>

Go to the Sign build step:

 ![Screen Shot 2023-07-07 at 16.13.32](https://forum.xojo.com/uploads/default/original/2X/f/fdd0fbc53ab6cf952a4e338ff97582884ab67098.jpeg)

---

<div class="post-metadata">

**Author:** ![TimStreater](https://forum.xojo.com/user_avatar/forum.xojo.com/timstreater/32/586_2.png) [@TimStreater](https://forum.xojo.com/u/TimStreater)\
**Post date:** [July 7, 2023, 2:15pm UTC](https://forum.xojo.com/t/code-signing-app/76407/12 "2023-07-07T14:15:46Z")

</div>

For macOS, look at macOS in the Build Settings part of the navigator pane, expend that, and click on Sign.

---

<div class="post-metadata">

**Author:** ![John\_Fatte](https://forum.xojo.com/letter_avatar_proxy/v4/letter/j/4bbf92/32.png) [@John\_Fatte](https://forum.xojo.com/u/John_Fatte)\
**Post date:** [July 7, 2023, 6:56pm UTC](https://forum.xojo.com/t/code-signing-app/76407/13 "2023-07-07T18:56:24Z")

</div>

Decided to take the excellent advice from this forum.

Downloaded and purchased AppWrapper and when setting up code sign, it says that I am “missing private key required for signing”. Not exactly sure how to get a private key for my certificates?

---

<div class="post-metadata">

**Author:** ![Rick\_Araujo](https://forum.xojo.com/user_avatar/forum.xojo.com/rick_araujo/32/251_2.png) [@Rick\_Araujo](https://forum.xojo.com/u/Rick_Araujo)\
**Post date:** [July 7, 2023, 10:34pm UTC](https://forum.xojo.com/t/code-signing-app/76407/14 "2023-07-07T22:34:55Z")

</div>

> **[Manage Certificates](https://ohanaware.com/appwrapper/aw4/help/en.lproj/guides/downloadAndInstallCerts.html)**
>
> How to download, install and remove code signing certificates from a Mac

---

<div class="post-metadata">

**Author:** ![John\_Fatte](https://forum.xojo.com/letter_avatar_proxy/v4/letter/j/4bbf92/32.png) [@John\_Fatte](https://forum.xojo.com/u/John_Fatte)\
**Post date:** [July 8, 2023, 2:56am UTC](https://forum.xojo.com/t/code-signing-app/76407/15 "2023-07-08T02:56:28Z")

</div>

Rick, I deleted and recreated all the certificates (Mac Development, Developer ID Installer, and Developer ID Application) with a new CSR that I created on my computer. I then added them to Keychain and yet AppWrapper still says I’m missing a private key. Any ideas how to correct this issue?

---

<div class="post-metadata">

**Author:** ![Thomas\_Roemert](https://forum.xojo.com/user_avatar/forum.xojo.com/thomas_roemert/32/827_2.png) [@Thomas\_Roemert](https://forum.xojo.com/u/Thomas_Roemert)\
**Post date:** [July 8, 2023, 5:07am UTC](https://forum.xojo.com/t/code-signing-app/76407/16 "2023-07-08T05:07:52Z")

</div>

> [@John\_Fatte](#):
>
> Any ideas how to correct this issue?

Yes, use Xcode to manage your certificates.

---

<div class="post-metadata">

**Author:** ![DetlefK](https://forum.xojo.com/user_avatar/forum.xojo.com/detlefk/32/23653_2.png) [@DetlefK](https://forum.xojo.com/u/DetlefK)\
**Post date:** [July 8, 2023, 6:40pm UTC](https://forum.xojo.com/t/code-signing-app/76407/17 "2023-07-08T18:40:17Z")

</div>

As Thomas R. mentioned, do not manage the certificates manually,  
but use XCode to manage them.

---

<div class="post-metadata">

**Author:** ![Greg\_O](https://forum.xojo.com/user_avatar/forum.xojo.com/greg_o/32/22785_2.png) [@Greg\_O](https://forum.xojo.com/u/Greg_O)\
**Post date:** [July 8, 2023, 7:51pm UTC](https://forum.xojo.com/t/code-signing-app/76407/18 "2023-07-08T19:51:13Z")

</div>

Just FYI, the problem with using Xcode is that it likes to create some certificates that are not compatible with Xojo… specifically wildcard certs.

It is possible to get this to work and manage them yourself (that’s how I do it) and get some diagnostics using my Profile Triage app which is available on my [website](https://www.stretchedout.com/yaxew/).

Going back to your question though… usually the reason the private key is missing is that you didn’t store it in your keychain the first time you downloaded it. After that, the only thing you can download is the public key, and you can’t sign with that. The remedy is to delete the key and create a new one from scratch.

I also suggest reading my blog post about this…

> **[The Crazy Exercise that is the Apple Signing Process – Xojo Programming Blog](https://blog.xojo.com/2021/10/26/the-crazy-exercise-that-is-the-apple-signing-process/)**
