Sign custom JRE for an Java App in macOS Catalina

Viewed 193

I bundled my java application as an.app. Inside this bundle is a jre, created with jLink. (Contents/Resources/jre/jre_11.../) I now try to sign it with --deep so it signs everything recursively, but it doesn't seem to work. When I try to notarise the app, I get an error, that the bin files and dynamic libraries are not signed.

This is the command I use:

codesign --force --deep --timestamp --entitlements ./sign.entitlements --options runtime --sign "AppleDevIDStuff" ../../../Desktop/Launch.app/
  • code sign doesn't give me any errors
  • command codesign -vvv --deep --strict ../../../Desktop/Launch.app/ says everything is ok
  • If I try to sign Contents/Resources/jre/jre_.../bin I get an error, saying this directory is not a valid bundle (which is true)
  • Signing the JRE as a directory for itself, outside the app, gives me the same error (Not a valid package)
  • jPackage cannot be used, because it produces a different layout for .app, my application needs a specific layout for the contents inside .app.

I didn't find any guide how to sign a custom created JRE and somehow I'm unable to sign this.

So the question is basically: How to sign a custom JRE created with jLink?

0 Answers
Related