Inno Setup code signing not applying for all the files. How to fix that?

Viewed 195

We are using a setup creation tool called Inno Setup to get the final installation file. In there we are using signtool.exe to sign all the files of our app. We put necessary details in these boxes enter image description here

We are using a certificate called DMCC_Microsoft_Key.pfx But after the creation of the setup and when we install the setup only the application.exe file shows digital signatures while other files do not show that. Here is the script in signtool

"c:\{path}\signtol.exe" sign /f "{Certificate path}\key.pfx" /tr "http://timestamp.digicert.com" /p "Password" $f

The below digital signatures tab is only shown in the .exe file.

enter image description here

How to sign in all the DLLs inside a given directory using Inno Setup?

This is my iss script

;#define APP_EXE_NAME "AsiaMX TY 6.exe"

[Setup]
SignTool=ASIAMX_signtool

[Files]
Source: "{#APP_EXE_NAME}"; DestDir: "{app}"; \
    Flags: ignoreversion signonce; Permissions: everyone-full
Source: "*"; DestDir: "{app}"; \
    Flags: ignoreversion recursesubdirs createallsubdirs; \
    Permissions: everyone-full

I saw some other StackOverflow questions. Another one answered the same kind of question using this answer. I don't know where to put this. How to sign every ocx, dll and exe file

Try

@echo off FOR /f "tokens=*" %%G IN ('dir /s *.dll *.ocx *.exe') DO ( echo %%G set A= "%%G" signtool sign /f "C:\Certificates\FakeCertificate.pfx" %A% )
2 Answers

You have the signonce flag only at the {#APP_EXE_NAME} entry. Not on the others.

So not surprisingly, Inno Setup signs only the {#APP_EXE_NAME}, not the other files.

As the * entry matches both executable and non-executable files, you have to the split the entry to two. And actually your {#APP_EXE_NAME} entry conflicts too with the * entry.

This should do:

[Files]
Source: "{#APP_EXE_NAME}"; DestDir: "{app}"; \
    Flags: ignoreversion signonce; Permissions: everyone-full
Source: "*.dll"; DestDir: "{app}"; \
    Flags: ignoreversion recursesubdirs createallsubdirs signonce; \
    Permissions: everyone-full
Source: "*"; Excludes: "{#APP_EXE_NAME},*.dll" DestDir: "{app}"; \
    Flags: ignoreversion recursesubdirs createallsubdirs; \
    Permissions: everyone-full

This is a good question, however perhaps you need to consider that signing a dll that doesn't belong to you might/will cause a antivirus to flag the file as suspicious. You better make sure that they are all yours before you claim them to be yours ;-)

I'm not aware of any method in inno to do this, I guess you could "hack it" and write a pascal method that injects this feature.

[Setup]
AppVersion={code:SignAndGetVersion}


[Code]

function SignAndGetVersion(Param: String): String;
begin
    { some magic selecting your dll's and calling signtool.exe... }
    Result := '1.2.3';
end;

however... if you are already calling sign-tool then why do it in inno setup?

perhaps a bat file like so:

for %%f in (X:\InnoSetup_source\*.dll) do "c:\{path}\signtol.exe" sign /f "{Certificate path}\key.pfx" /tr "http://timestamp.digicert.com" /p "Password" "%%f" 

or include the instructions in your post build. I do

<Target Name="PostBuild" AfterTargets="PostBuildEvent">
        <Exec Command="signtool.exe sign /i Sectigo /t http://timestamp.sectigo.com /fd SHA384 &quot;$(TargetPath)&quot;" Condition="$(Configuration) == 'Release'" />
        <Exec Command="signtool.exe sign /i Sectigo /t http://timestamp.sectigo.com /fd SHA384 &quot;$(TargetDir)IDPS.exe&quot;" Condition="$(Configuration) == 'Release'" />
        <Exec Command="signtool.exe sign /i Sectigo /fd SHA384 &quot;$(TargetPath)&quot;" Condition="$(Configuration) != 'Release'" />
        <Exec Command="signtool.exe sign /i Sectigo /fd SHA384 &quot;$(TargetDir)IDPS.exe&quot;" Condition="$(Configuration) != 'Release'" />
    </Target>
Related