Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 7 additions & 1 deletion docs/packaging/cross-compiling.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,13 @@ Before running a command for a different OS, you should review the help text of
you must use a MacOS machine to create MacOS packages.

## Signing caveat
While you can *build* a Windows package from Linux or macOS, **signing** it has additional requirements. The standard `--signParams` / `--signTemplate` path relies on `signtool.exe`, which only runs on Windows. If you need to sign a Windows package from Linux or macOS, use a cross-platform tool such as JSign. See the [code signing guide](./signing.mdx) for details.
Windows packages built on Linux or macOS can also be signed there, using `--signTemplate`. It runs whatever command you give it, so any cross-platform signing tool works:

```sh
vpk [win] pack ... --signTemplate "<your tool> sign {{file...}}"
```

What does *not* work off Windows is `--signParams` and `--azureTrustedSignFile`, both of which invoke the bundled `signtool.exe`. See [Cross Platform Signing](./signing.mdx#cross-platform-signing) for tools that fill the gap.



Expand Down
4 changes: 3 additions & 1 deletion docs/packaging/signing.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,9 @@ Note that since June 1, 2023 there [has been a policy change](https://knowledge.
For detailed information on Azure Artifact Signing please refer to the [official documentation](https://learn.microsoft.com/azure/trusted-signing/).

:::note
Signing relies on `signtool.exe` which is only supported on Windows. If you are using a different operating system, you will need to sign your binaries on a Windows machine before deploying them.
`--signParams` and `--azureTrustedSignFile` rely on `signtool.exe`, which only runs on Windows. Signing with either of those on Linux or macOS is not possible.

`--signTemplate` has no such restriction: it runs whatever command you give it, on any operating system. See [Cross Platform Signing](#cross-platform-signing) below.
:::

1. First you will need to create an Azure account at: https://azure.microsoft.com/pricing/purchase-options/azure-account. This account will need to have an [active subscription](https://learn.microsoft.com/azure/cost-management-billing/manage/create-subscription#create-a-subscription).
Expand Down