Lesson 15 of 28 · javascript
Code Signing – macOS & Windows
Duration: 9 mins
Code Signing – macOS & Windows
macOS notarization (Gatekeeper)
- Enroll in the Apple Developer Program.
- Export a Developer ID Application certificate.
- Sign the app bundle:
codesign --deep --force --options runtime --entitlements entitlements.plist \
--sign "Developer ID Application: Your Name (TEAMID)" MyApp.app
- Notarize with
xcrun altool(ornotarytoolin newer Xcode):
xcrun notarytool submit MyApp.app --apple-id YOUR_ID --password APP_SPECIFIC_PASSWORD --team-id TEAMID
- Once notarized, staple the ticket:
xcrun stapler staple MyApp.app
Windows code signing
- Purchase a code‑signing certificate (or use a free OpenSSL self‑signed cert for testing).
- Sign the executable with
signtool:
signtool sign /f cert.pfx /p YOUR_PASSWORD /tr http://timestamp.digicert.com /td sha256 /fd sha256 dist/MyApp Setup.exe
- Verify:
signtool verify /pa /v dist/MyApp Setup.exe
Both platforms require the signature to be embedded before creating the installer; electron-builder can run the signing step automatically if you provide the appropriate config.