如何使用Maven JarSigner签名多个Jars

时间:2018-10-22 16:34:08

标签: java maven maven-jarsigner-plugin

我有一个程序可以从maven-assembly-plugin生成两个JAR文件。我想使用maven-jarsigner-plugin对两个罐子进行签名。当我应用基本jarsigner时,它仅对JARS之一进行签名。当我添加存档目录字段时:

<archiveDirectory>${project.basedir}/target</archiveDirectory>    

它要么通过通用的“执行失败”的符号命令失败,要么在签名第二个jar时无法将.jar重命名为.jar.orig。唯一可能会使用jar的是构建过程本身。其他人看到了吗?当我删除上面的“ archiveDirectory”行并仅构建一个jar,并注释掉另一个jar时,此方法效果很好。

<build>
    <plugins>
        <plugin>
            <artifactId>maven-assembly-plugin</artifactId>
            <version>2.4</version>
            <executions>
                <execution>
                    <id>build-first</id>
                    <configuration>
                        <appendAssemblyId>false</appendAssemblyId>
                        <archive>
                            <manifest>
                                <mainClass>my.class.Executive</mainClass>
                            </manifest>
                            <manifestEntries>
                                <Class-Path>.</Class-Path>
                            </manifestEntries>
                        </archive>
                        <descriptorRefs>
                            <descriptorRef>jar-with-dependencies</descriptorRef>
                        </descriptorRefs>
                        <finalName>DaExecutive</finalName>
                    </configuration>
                    <phase>package</phase>
                    <goals>
                        <goal>single</goal>
                    </goals>
                </execution>
                <execution>
                    <id>build-second</id>
                    <configuration>
                        <appendAssemblyId>false</appendAssemblyId>
                        <archive>
                            <manifest>
                                <mainClass>my.class.ExampleGUI</mainClass>
                            </manifest>
                            <manifestEntries>
                                <Class-Path>.</Class-Path>
                            </manifestEntries>
                        </archive>
                        <descriptorRefs>
                            <descriptorRef>jar-with-dependencies</descriptorRef>
                        </descriptorRefs>
                        <finalName>ExampleAppGui</finalName>
                    </configuration>
                    <phase>package</phase>
                    <goals>
                        <goal>single</goal>
                    </goals>
                </execution>
            </executions>
        </plugin>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-jarsigner-plugin</artifactId>
            <version>1.4</version>
            <executions>
                <execution>
                    <id>sign</id>
                    <goals>
                        <goal>sign</goal>
                    </goals>
                </execution>
            </executions>
            <configuration>

              <archiveDirectory>${project.basedir}/target</archiveDirectory>                   
                <keystore>${project.basedir}/myKeystore.jks</keystore>
                <storepass>pw</storepass>
                <alias>ABC</alias>
                <verify>false</verify>
            </configuration>
        </plugin>
    </plugins>
</build>

这是详细的错误输出:

[DEBUG] Processing     C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\ExampleAppGui.jar
[DEBUG] cmd.exe /X /C ""C:\Program Files\Java\jdk1.8.0_181\jre\..\bin\jarsigner.exe" -keystore C:\Users\atalak\Desktop\GitRepo\DataAdapter/myKeystore.jks -storepass ***** C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\ExampleAppGui.jar key_2017"
[DEBUG] Executing: cmd.exe /X /C ""C:\Program Files\Java\jdk1.8.0_181\jre\..\bin\jarsigner.exe" -keystore C:\Users\atalak\Desktop\GitRepo\DataAdapter/myKeystore.jks -storepass ***** C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\ExampleAppGui.jar key_2017"
[DEBUG] jar signed.
[DEBUG] 
[DEBUG] Warning: 
[DEBUG] The signer certificate will expire within six months.
[DEBUG] No -tsa or -tsacert is provided and this jar is not timestamped. Without a timestamp, users may not be able to validate this jar after the signer certificate's expiration date (2019-03-15) or after any future revocation date.
[DEBUG] Processing C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar
[DEBUG] cmd.exe /X /C ""C:\Program Files\Java\jdk1.8.0_181\jre\..\bin\jarsigner.exe" -keystore C:\Users\atalak\Desktop\GitRepo\DataAdapter/myKeystore.jks -storepass ***** C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar key_2017"
[DEBUG] Executing: cmd.exe /X /C ""C:\Program Files\Java\jdk1.8.0_181\jre\..\bin\jarsigner.exe" -keystore C:\Users\atalak\Desktop\GitRepo\DataAdapter/myKeystore.jks -storepass ***** C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar key_2017"
[DEBUG] jarsigner: attempt to rename C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar to C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar.orig failed
[INFO] ------------------------------------------------------------------------
[INFO] BUILD FAILURE
[INFO] ------------------------------------------------------------------------
[INFO] Total time: 36.631 s
[INFO] Finished at: 2018-10-22T12:29:33-04:00
[INFO] Final Memory: 28M/694M
[INFO] ------------------------------------------------------------------------
[ERROR] Failed to execute goal org.apache.maven.plugins:maven-jarsigner-plugin:1.4:sign (sign) on project DataAdapter: Failed executing 'cmd.exe /X /C ""C:\Program Files\Java\jdk1.8.0_181\jre\..\bin\jarsigner.exe" -keystore C:\Users\atalak\Desktop\GitRepo\DataAdapter/myKeystore.jks -storepass ***** C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar key_2017"' - exitcode 1 -> [Help 1]
org.apache.maven.lifecycle.LifecycleExecutionException: Failed to execute goal org.apache.maven.plugins:maven-jarsigner-plugin:1.4:sign (sign) on project DataAdapter: Failed executing 'cmd.exe /X /C ""C:\Program Files\Java\jdk1.8.0_181\jre\..\bin\jarsigner.exe" -keystore C:\Users\atalak\Desktop\GitRepo\DataAdapter/myKeystore.jks -storepass ***** C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar key_2017"' - exitcode 1
    at org.apache.maven.lifecycle.internal.MojoExecutor.execute(MojoExecutor.java:212)
    at org.apache.maven.lifecycle.internal.MojoExecutor.execute(MojoExecutor.java:153)
    at org.apache.maven.lifecycle.internal.MojoExecutor.execute(MojoExecutor.java:145)
    at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject(LifecycleModuleBuilder.java:116)
    at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject(LifecycleModuleBuilder.java:80)
    at org.apache.maven.lifecycle.internal.builder.singlethreaded.SingleThreadedBuilder.build(SingleThreadedBuilder.java:51)
    at org.apache.maven.lifecycle.internal.LifecycleStarter.execute(LifecycleStarter.java:128)
    at org.apache.maven.DefaultMaven.doExecute(DefaultMaven.java:307)
    at org.apache.maven.DefaultMaven.doExecute(DefaultMaven.java:193)
    at org.apache.maven.DefaultMaven.execute(DefaultMaven.java:106)
    at org.apache.maven.cli.MavenCli.execute(MavenCli.java:863)
    at org.apache.maven.cli.MavenCli.doMain(MavenCli.java:288)
    at org.apache.maven.cli.MavenCli.main(MavenCli.java:199)
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
    at java.lang.reflect.Method.invoke(Method.java:498)
    at org.codehaus.plexus.classworlds.launcher.Launcher.launchEnhanced(Launcher.java:289)
    at org.codehaus.plexus.classworlds.launcher.Launcher.launch(Launcher.java:229)
    at org.codehaus.plexus.classworlds.launcher.Launcher.mainWithExitCode(Launcher.java:415)
    at org.codehaus.plexus.classworlds.launcher.Launcher.main(Launcher.java:356)
Caused by: org.apache.maven.plugin.MojoExecutionException: Failed executing 'cmd.exe /X /C ""C:\Program Files\Java\jdk1.8.0_181\jre\..\bin\jarsigner.exe" -keystore C:\Users\atalak\Desktop\GitRepo\DataAdapter/myKeystore.jks -storepass ***** C:\Users\atalak\Desktop\GitRepo\DataAdapter\target\DaExecutive.jar key_2017"' - exitcode 1
    at org.apache.maven.plugins.jarsigner.AbstractJarsignerMojo.processArchive(AbstractJarsignerMojo.java:515)
    at org.apache.maven.plugins.jarsigner.AbstractJarsignerMojo.execute(AbstractJarsignerMojo.java:343)
    at org.apache.maven.plugin.DefaultBuildPluginManager.executeMojo(DefaultBuildPluginManager.java:134)
    at org.apache.maven.lifecycle.internal.MojoExecutor.execute(MojoExecutor.java:207)
    ... 20 more
[ERROR] 
[ERROR] 
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException

2 个答案:

答案 0 :(得分:0)

检查this项目,我已经根据您的代码完成了它。

它签署了3个jar档案。

我的插件标签如下:

<plugin>
                <groupId>org.apache.maven.plugins</groupId>
                <artifactId>maven-jarsigner-plugin</artifactId>
                <version>1.4</version>
                <executions>
                    <execution>
                        <id>sign</id>
                        <goals>
                            <goal>sign</goal>
                        </goals>
                    </execution>
                    <execution>
                        <id>verify</id>
                        <goals>
                            <goal>verify</goal>
                        </goals>
                    </execution>
                </executions>
                <configuration>
                    <verbose>true</verbose>
                    <certs>true</certs>
                    <keystore>${basedir}/server.jks</keystore>
                    <alias>server</alias>
                    <storepass>masterkey</storepass>
                    <keypass>masterkey</keypass>
                </configuration>
            </plugin>

这似乎是唯一的区别。

运行:

  

MVN清洁包

生成存档。

最后,我弄清楚了它为什么不起作用:删除<appendAssemblyId>false</appendAssemblyId> 从两个处决。我在GitHub上提交了源代码。

答案 1 :(得分:0)

您在maven-jarsigner-plugin中设置了目录,也许他是锁定您文件的目录 为每个罐子尝试1个插件

    <plugin>
        <groupId>org.apache.maven.plugins</groupId>
        <artifactId>maven-jarsigner-plugin</artifactId>
        <version>1.4</version>
        <executions>
            <execution>
                <id>sign</id>
                <goals>
                    <goal>sign</goal>
                </goals>
            </execution>
        </executions>
        <configuration>
            <archive>${project.basedir}/target/ExampleAppGui.jar</archive>
            <keystore>${project.basedir}/myKeystore.jks</keystore>
            <storepass>pw</storepass>
            <alias>ABC</alias>
            <verify>false</verify>
        </configuration>
    </plugin>

    <plugin>
        <groupId>org.apache.maven.plugins</groupId>
        <artifactId>maven-jarsigner-plugin</artifactId>
        <version>1.4</version>
        <executions>
            <execution>
                <id>sign</id>
                <goals>
                    <goal>sign</goal>
                </goals>
            </execution>
        </executions>
        <configuration>
            <archive>${project.basedir}/target/DaExecutive.jar</archive>
            <keystore>${project.basedir}/myKeystore.jks</keystore>
            <storepass>pw</storepass>
            <alias>ABC</alias>
            <verify>false</verify>
        </configuration>
    </plugin>