[quote='850201022, tomdesantis, /thread/794045?answerId=850201022#850201022, /profile/tomdesantis'] it sounds like you are skipping the stapling step. [/quote] That seems unlikely. Stapling is only required if the user runs the app on a Mac that doesn’t have access to Apple’s servers. I explain this in The Pros and Cons of Stapling. [quote='850201022, tomdesantis, /thread/794045?answerId=850201022#850201022, /profile/tomdesantis'] 7. Only after stapling, create the distribution image. [/quote] That’ll work, but my preference is to notarise the outermost container. So, if your ultimate plan is to distribute a disk image, create the disk image, sign it, notarise it, and then staple to the disk image. There’s a lot more info about this stuff in: Creating distribution-signed code for macOS Packaging Mac software for distribution [quote='794045021, evgzap, /thread/794045, /profile/evgzap'] Why would the app be treated as malicious on other systems even after notarization? [/quote] Gatekeeper and notarisat
Topic:
Code Signing
SubTopic:
General
Tags: