Create a Code Signing Certificate for electron and add it to nsis installer

Viewed 347

I am new to electron and I am getting an unknown publisher error each time I deploy my application on a PC. I have tried disabling User Account Control Settings but it only worked on some windows 10, plus it is not a good way to solve the problem.

And after some research, I found that I can create a self-signed certificate using electron-builder:

electron-builder create-self-signed-cert -p Name

When I am running this cmd I am getting a .pfx file certificate. Now, following this documentation, I know that to sign the app on the build server I need to set CSC_LINK, CSC_KEY_PASSWORD. (how do I set the CSC link and key password? do I add them inside my package.json?)

First I need to export the certificate (do I just upload the certificate to a server?)

Second I need to encode file to base64 (after I uploaded the certificate do I encode it? from .pfx to txt?)

Moreover, is it better to attach the .pfx file to the nsis installer? or just use a server to handle this job?

I am so lost any help would go a long way. thanks for all your support.

1 Answers

Open your windows powershell(open start and type windows powershell) and enter these commands, you will be able to export the certificate to C:\Cert folder and then use it inside your package.json file.

$cert = New-SelfSignedCertificate -DNSName "www.domain.com" -CertStoreLocation Cert:\CurrentUser\My -Type CodeSigningCert -Subject “Example Code Signing Certificate”

$CertPassword = ConvertTo-SecureString -String "my_password" -Force -AsPlainText

Export-PfxCertificate -Cert "cert:\CurrentUser\My$($cert.Thumbprint)" -FilePath "C:\Cert$certificate.pfx" -Password $CertPassword

Your win inside package.json should look like this

"win": {
      "target": [
        "nsis"
      ],
      "publisherName":"microsoft",
      "certificateFile": "./certificate.pfx",
      "certificatePassword": "my_password"
    },

Put the certificate file in your project folder and give its path to certificateFile. NOTE: Use it for development purpose only as it is not an optimal way.

Mentions: https://sectigostore.com/page/how-do-i-generate-a-self-signed-code-signing-certificate

Related