InstallAware for Windows Installer
 

Code Signing Hooks

Code signing hooks let you run custom application(s) any time code signing would occur on any file that is part or product of your build. To access your code signing hooks:

  • Press SHIFT+CTRL+F11.
  • On the Project tab, in the Manage group, click Project Settings.
  • On the MSIcode tab, in the Compile group, click Project Settings.

Code Signing Hooks Node

This page lets you configure your code signing hooks. Code signing hooks do not trigger unless authenticode signing has been enabled.

Commands

Specify one command on each line of this field.

You may run as many custom applications as necessary for your code signing to succeed. Each command executes sequentially in the order provided. Should any of the commands specified in this field, your build will fail due to a code signing error.

Enclose paths to applications containing spaces within double quotes (").

Enclose application parameters containing spaces within double quotes as well ("), otherwise each space delineates a new application command line parameter.

If you use compiler variables in this field, most commonly to reference the project folder (#PROJDIR#) and the InstallAware toolchain folder (#IADIR#), they will be resolved to their literal values during a build process.

Example Workflow Using Azure Trusted Signing

As of this writing, you may complete the steps below to sign your binaries using Azure Trusted Signing.

Please note that you must already have an Azure account with Microsoft and have completed Trusted Signing identity validation.

Getting ready

  1. Install the latest version of the .NET 8 Runtime from https://dotnet.microsoft.com/en-us/download/dotnet/8.0.
  2. Install the latest version of the Visual C++ Runtime from https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170.
  3. Install the latest MSI of the Azure CLI from https://aka.ms/installazurecliwindowsx64 (64-bit) or https://aka.ms/installazurecliwindows (32-bit). Installing non-MSI versions of these command line tools from their main download page at https://learn.microsoft.com/en-us/cli/azure/install-azure-cli-windows may cause failures later in the process and is not recommended.
  4. Download the Microsoft Trusted Signing Client from https://www.nuget.org/packages/Microsoft.Trusted.Signing.Client using the Download package link under the About heading. Add a .zip file extension to the downloaded .nupkg file, and extract it using DiskZIP. This tutorial assumes you have extracted these files to the root of your c:\ drive using the Extract to Subfolder(s) File Explorer right-click action on the downloaded archive.
  5. Copy the file signtool.exe from your InstallAware installation folder to the c:\microsoft.trusted.signing.client.1.0.60.nupkg folder created in the step above.
  6. Create your code signing JSON file as described at https://learn.microsoft.com/en-us/azure/trusted-signing/how-to-signing-integrations#create-a-json-file and place it inside this same folder above with the file name file.json.
  7. Optionally, login to your Azure account by sequentially executing the commands described in the steps below from the command line. While these steps are optional, they prevent failures that may occur later in the process, and are recommended.

Logging on

  1. Run az login --user <your email address> --password <your password>. If this command fails, logon interactively instead running az login.
  2. Run az login --tenant <your tenancy GUID>.
  3. Run az account set --subscription "<your subscription GUID>". Please be advised that the GUIDs in the two steps above are supposed to be different from one another.

Signing code

  1. In the Project Options dialog (SHIFT+CTRL+F11), select the Authenticode node beneath the Build node, and check the Sign the package with Authenticode box. You do not need to fill in (or clear) any of the other fields on this page, as they will be ignored whether they are populated or not.
  2. Select the Code Signing Hooks node beneath the Build node, and type the command c:\microsoft.trusted.signing.client.1.0.60.nupkg\signtool.exe sign /v /fd SHA256 /tr "http://timestamp.acs.microsoft.com" /td SHA256 /dlib "c:\microsoft.trusted.signing.client.1.0.60.nupkg\bin\x64\Azure.CodeSigning.Dlib.dll" /dmdf "c:\microsoft.trusted.signing.client.1.0.60.nupkg\file.json" "%1" on a single line.

Your setups and code will now be signed using Azure Trusted Signing as an integral part of your build process, bestowing the benefit of instant trust on your packages.