Reproducible build and binary signing

Viewed 121

I'm developing an open source project and I have been working on making the builds reproducible so that my users can compare the checksums of the binaries that I distribute with their own builds (if they were to build the project with/from the source code).

Unfortunately, new versions of Windows and MacOS use code signing in order to check binaries and prevent their execution if they aren't signed (I'm aware that there are ways to override this and execute the binary anyways, but this is not user friendly).

I'd like to sign the binaries that I distribute so that my users can run them without any problems. But I'm not sure if that is possible to do while also keeping the reproducible builds.

For a build to be reproducible, the end user must have all the tools / source code required to build the project and, once compiled, the end result should be the same bit-a-bit binary compared to the one that I'm distributing. But that would mean that I'd have to distribute the private key / cert used to sign the binary, which is not a good idea for multiple reasons.

Is there a way to have both reproducible builds and signed binaries?

1 Answers

Here is a general approach for creating reproducible signed builds for open source.

Create your "sign binaries" script as follows:

  1. Compile project
  2. Make a checksum of the project's signing preimage
  3. Compare the checksum to the file SIGNING_CHECKSUM

If there is a match:

  1. Use the signature in SIGNING_SIGNATURE to build the package
  2. Verify that SIGNING_SIGNATURE was signed by SIGNING_PUBLIC_KEY

If there is not a match:

  1. Save the checksum to the file SIGNING_CHECKSUM
  2. Use the local signing key to sign the binary
  3. Save the signature to the file SIGNING_SIGNATURE
  4. Verify that SIGNING_SIGNATURE was signed by SIGNING_PUBLIC_KEY

End result is that anybody can reproducibly build the untampered source code. Anybody can edit the source code and reproducibly build the binary so long as the modifications to not modify the signing preimage. And only the developer with access to the signing key is able to sign new releases.

Related