Error, "The timestamp service is not available." when using codesign on Mac OS X 10.8

Viewed 10290

I'm signing an app bundle using an Apple Developer ID certificate. I need to sign using the the command line tool since our build is automated and runs from our toolchain. 90% of the time it works fine with this command:

ws5:bin nick$ codesign -fs "Developer ID Application: <my name here>" MyApp.app
ws5:bin nick$ spctl --assess MyApp.app
ws5:bin nick$ 

Note: MyApp.app is not my real application name, and <my name here> is not the actual value.

So, maybe 1 in 10 times it intermittently fails with this error:

MyApp.app: The timestamp service is not available.

I've verified the .app gets through the quarantine mechanism with spctl --assess and by zipping it and downloading the signed file -- so please don't say "you're doing it wrong, use Xcode". I know that Apple doesn't "officially" recommend using codesign for developer ID certificates (according to a WWDC video) but we need to use it for automation and because our app is a strange combination of gcc and Qt build output.

Is the best strategy around this error to just retry until it works again? That's all I can think to do.

6 Answers

Each time you try to do code signing it will interact with time.apple.com server. Sometime we find issue in connection with apple time server and code signing fails.

Two things we can do when we face this issue -

  1. ping time.apple.com

this will help us to check time server is working properly without any glitch.

  1. If above step won't work, last option is to reboot the machine.

This is the saver step and it always work because it restart the local apple time client.

If you don't want to restart the system, then you can find how to restart local apple time client. OR

  1. On one terminal - run ping time.apple.com and on 2nd terminal tab run codesign command continuously, this always works. And don't forget to run security unlock-keychain login.keychain before codesigning command.
Related