Codesign returned unknown error -1=ffffffffffffffff

Viewed 12174

I tried to code sign an iOS application, These are the steps that i followed

    security create-keychain -p password ${KEYCHAIN}
    security set-keychain-settings -u -t 300 ${KEYCHAIN}
    security list-keychains -d user -s login.keychain ${KEYCHAIN}
    security import "$1" -k ${KEYCHAIN} -A -P "${PASSPHRASE}" -A >/dev/null
    security unlock-keychain -p password ${KEYCHAIN}

    /usr/bin/codesign -f -s $IDENTITY --keychain $KEYCHAIN --entitlements $ENTITLEMENTS Payload/Test.app

This returned me Codesign returned unknown error -1=ffffffffffffffff via ssh.

If i directly execute the code sign command in the machine, it's successfully signing.

The issue is only in Mac OS Sierra.

8 Answers

@madhu I have been trying to fix the same issue and found that Access Control for the key associated with the certificate in question was set to "Confirm before allowing access" which didn't work in Jenkins. I modified it (thru Keychain Access gui - Get Info, Access Control) to "Allow all applications to access this item" and my build was successful.

Even though we installed the right certs in the keychain and the right Provisioning Profile under ~/Library/MobileDevices/Provisioning Profiles.

We may also see

unknown error -1=ffffffffffffffff

For this error, I tried the below steps to fixed the issue:

  1. Reboot the machine, unlock keychain using "securify unlock-keychain", lock the keychain again
  2. Remove ~/Library/Developer/Xcode/DerivedData folder.
  3. Run carthage bootstrap --platform iOS
  4. Open the source code syncing down workspace, run "xattr -rc ." then open the .xcodeproject file in xcode.
  5. Turned on the automatic signing for each target. Need to login with valid credentials.
  6. Click on the provisioning profile under signing.
  7. unlock the keychain again
  8. Changing the build device to Generic Devices, under Product --> Clean, then Product –> Archive
  9. There will be a keychain access allow showed up, click "Always Allow".
  10. You should make sure the archive is successful then trigger the Jenkins job again.
Related