Re: Notarization error: The signature algorithm used is too weak

2019-05-28 Thread Richard Charles via Cocoa-dev


> On May 28, 2019, at 3:43 PM, Leo via Cocoa-dev  
> wrote:
> 
> -I recently contacted Apple again and they pointed me to some resource page 
> that was created back in 2016. It briefly mentions a similar error - but 
> still without any info on how to solve it:
> https://developer.apple.com/library/archive/technotes/tn2206/_index.html#//apple_ref/doc/uid/DTS40007919-CH1-TNTAG301
>  
> 
> -A search on this error didn't produce anything useful.
> 
> -The tar.gz file in question is an eSellerate licensing framework. As many 
> people may know, it's been a popular licensing??platform for Mac software for 
> over a decade. While I switched to a different licensing platform some time 
> ago, I still have thousands of customers with eSellerate licenses (as I'm 
> sure is the situation with many other Mac developers).
> 
> As far as I understand, this whole situation has to do something with signing 
> files inside tar.gz archives - on which I couldn't find any info either

Looks to me like your eSellerate framework is signed with a version 1 
signature. You need to resign the framework with a version 2 signature.

--Richard Charles

___

Cocoa-dev mailing list (Cocoa-dev@lists.apple.com)

Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com

Help/Unsubscribe/Update your Subscription:
https://lists.apple.com/mailman/options/cocoa-dev/archive%40mail-archive.com

This email sent to arch...@mail-archive.com


Notarization error: The signature algorithm used is too weak

2019-05-28 Thread Leo via Cocoa-dev




Hi all,

I wonder if anyone's familiar with this error which only happens when I 
send my apps for notarization:


"AppName.zip/AppName.app/Contents/Resources/EWSMacCompress.tar.gz/EWSMacCompress.tar/EWSMac.framework/Versions/A/EWSMac83886082"
"The signature algorithm used is too weak."


Additional info:

-I've been signing my apps for years with no issues. The error only 
happens when sending the apps for notarization.


-I submitted a bug back in November 2018, provided Apple all the info 
they asked for - but it was never addressed further.


-I recently contacted Apple again and they pointed me to some resource 
page that was created back in 2016. It briefly mentions a similar error 
- but still without any info on how to solve it:
https://developer.apple.com/library/archive/technotes/tn2206/_index.html#//apple_ref/doc/uid/DTS40007919-CH1-TNTAG301 



-A search on this error didn't produce anything useful.

-The tar.gz file in question is an eSellerate licensing framework. As 
many people may know, it's been a popular licensing??platform for Mac 
software for over a decade. While I switched to a different licensing 
platform some time ago, I still have thousands of customers with 
eSellerate licenses (as I'm sure is the situation with many other Mac 
developers).


As far as I understand, this whole situation has to do something with 
signing files inside tar.gz archives - on which I couldn't find any info 
either



Any help will be appreciated!


Thanks,
Leo

___

Cocoa-dev mailing list (Cocoa-dev@lists.apple.com)

Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com

Help/Unsubscribe/Update your Subscription:
https://lists.apple.com/mailman/options/cocoa-dev/archive%40mail-archive.com

This email sent to arch...@mail-archive.com