I'd like to import a cert (x509) to local keystore (win and macOS). With this electron app user can create a website locally and can enable HTTPS that's why we need to store the cert.
The issue:
In some rare cases the user get an error message during cert import only on macOS:
Command failed: security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /Users/user/ssl/asdasd.local.crt SecTrustSettingsSetTrustSettings: The authorization was denied since no user interaction was possible.
If the user run the exact same command with sudo in terminal it works as expected.
Note: All users who get this error message has enabled apple watch authentication, but we know a user who has also enabled apple watch auth end he didn't get error message.
What we do:
In electron renderer process we run the following commands with sudo-prompt npm package. Every time first we delete the cert from keystore if it does exist and add the new one.
Windows add cert:
certutil -addstore -f ROOT C:\Users\user\ssl\asdasd.local.crt
Windows delete cert:
certutil -delstore ROOT asdasd.local
macOS add cert:
security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /Users/user/ssl/asdasd.local.crt
macOS delete cert:
security delete-certificate -c asdasd.local
UPDATE
I've opened an issue in sudo-prompt repo: https://github.com/jorangreef/sudo-prompt/issues/137
M1 mac asks password twice.
UPDATE 2
I've just realized this issue does not related to M1. Maybe related to Big Sur 11.1.
It looks like sudo-prompt package hides the second password dialog.
UPDATE 3
The command stores the cert in keychain but the trust value is not "Always trust" if the error occurs.
UPDATE 4
I've tried osascript way. It works perfectly on Big Sur 11.0, but It gave the same error on M1 Big Sur 11.1. (screenshot attached)
How am I trying to test?
running the following command:
const sudo = require('sudo-prompt')
sudo.exec(
'security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /Users/kotapeter/ssl/test.local.crt',
{
name: 'test',
},
(error, stdout) => {
if (error) {
console.log(error)
} else {
console.log(stdout)
}
}
)


