I bundled my java application as an.app. Inside this bundle is a jre, created with jLink. (Contents/Resources/jre/jre_11.../) I now try to sign it with --deep so it signs everything recursively, but it doesn't seem to work. When I try to notarise the app, I get an error, that the bin files and dynamic libraries are not signed.
This is the command I use:
codesign --force --deep --timestamp --entitlements ./sign.entitlements --options runtime --sign "AppleDevIDStuff" ../../../Desktop/Launch.app/
- code sign doesn't give me any errors
- command
codesign -vvv --deep --strict ../../../Desktop/Launch.app/says everything is ok - If I try to sign
Contents/Resources/jre/jre_.../binI get an error, saying this directory is not a valid bundle (which is true) - Signing the JRE as a directory for itself, outside the app, gives me the same error (Not a valid package)
- jPackage cannot be used, because it produces a different layout for
.app, my application needs a specific layout for the contents inside.app.
I didn't find any guide how to sign a custom created JRE and somehow I'm unable to sign this.
So the question is basically: How to sign a custom JRE created with jLink?