# Notarizing after Code-Signing?

**URL:** <https://forum.juce.com/t/notarizing-after-code-signing/39351>\
**Category:** Audio Plugins\
**Created:** [May 11, 2020, 7:30pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351 "2020-05-11T19:30:16Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 11, 2020, 7:30pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/1 "2020-05-11T19:30:16Z")

</div>

So I have successfully signed my plugins, however notarizing them seems to be a whole other issue. I have taken all the steps necessary I think.

1. Xcode 10 compatibility
2. Harden Runtime in Xcode Project

If I just add these two commands to after my signing commands it should work, right?  
I am still getting an error that my file is invalid. Am I missing anything?

–notarize-username YOUR\_APPLE\_ID  
–notarize-password @keychain:APP\_PASSWORD\_ITEM\_NAME

---

<div class="post-metadata">

**Author:** ![Verbonaut](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/verbonaut/32/11824_2.png) [@Verbonaut](https://forum.juce.com/u/Verbonaut)\
**Post date:** [May 11, 2020, 8:04pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/2 "2020-05-11T20:04:13Z")

</div>

Usually you’d want to notarise the installer. Scripts to help are in [this thread](https://forum.juce.com/t/apple-gatekeeper-notarised-distributables/29952).

---

<div class="post-metadata">

**Author:** ![jnicol](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/jnicol/32/1532_2.png) [@jnicol](https://forum.juce.com/u/jnicol)\
**Post date:** [May 11, 2020, 8:15pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/3 "2020-05-11T20:15:58Z")

</div>

I think the two flags you mentioned are for xcrun altool, but it sounds like you’re adding them to the Projucer?

I found the first post on this KVR thread very helpful: [https://www.kvraudio.com/forum/viewtopic.php?t=531663](https://www.kvraudio.com/forum/viewtopic.php?t=531663)

As @hill_matthew said, you possibly want to notarize a plugin installer (e.g. .pkg) but if it helps here are my notes for notarizing a single plugin:

Zip your vst/vst3/component, then on the command line:

```
xcrun altool --notarize-app --primary-bundle-id "PLUGIN IDENTIFIER" --username "EMAIL" --password "APP-SPECIFIC-PASSWORD" --asc-provider "SHORTNAME" --file file.zip

```

–primary-bundle-id: Anything you like. Should probably be unique to your plugin.  
–username: Your Apple ID username/email  
–password: An app-specific password ([https://support.apple.com/en-us/HT204397](https://support.apple.com/en-us/HT204397))  
–asc-provider: Only required if you are a member of more than one Apple developer team

Wait a few moments while your file is upload. A success message will be displayed and Apple will email you too.

Once your notarization is confirmed, you should (but don’t have to) staple the notarization ticket to the software, so that users can open it even without internet access:

```
xcrun stapler staple file.vst

```

Test that the file is notarized:

```
codesign --test-requirement="=notarized" --verify --verbose file.vst
```

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 11, 2020, 11:07pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/4 "2020-05-11T23:07:28Z")

</div>

I’ll try this out now.

I was trying to notarize with Eden while I code sign, but maybe it’s easier to code sign then notarize. I’ll check back. After I have succeeded or failed a few times.

Thanks @jnicol & @hill_matthew

---

<div class="post-metadata">

**Author:** ![jnicol](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/jnicol/32/1532_2.png) [@jnicol](https://forum.juce.com/u/jnicol)\
**Post date:** [May 11, 2020, 11:21pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/5 "2020-05-11T23:21:06Z")

</div>

Possibly a naive question, but what is Eden?

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 11, 2020, 11:22pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/6 "2020-05-11T23:22:02Z")

</div>

It’s how you code sign your binaries for AAX.  
So your plugins work in protools.

Aka iLok

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 11, 2020, 11:22pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/7 "2020-05-11T23:22:23Z")

</div>

2020-05-11 16:20:44.329 altool[32168:561555] \*\*\* Error: Unable to notarize app.

2020-05-11 16:20:44.329 altool[32168:561555] \*\*\* Error: code -22016 (Unable to validate your application. We are unable to create an authentication session.)

I followed your instructions, however I am getting these errors.

---

<div class="post-metadata">

**Author:** ![jnicol](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/jnicol/32/1532_2.png) [@jnicol](https://forum.juce.com/u/jnicol)\
**Post date:** [May 11, 2020, 11:39pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/8 "2020-05-11T23:39:00Z")

</div>

I’m far from an expert in this area (just muddling my way through), but some things I’d check:

Is the plugin properly code signed?

```
codesign -dvv "path/to/file.vst"

```

Does the result show a timestamp? e.g. Timestamp=XXXX

Are all the arguments for your altool command correct?

EDIT: I’m not sure if this process differs at all for AAX, since I’ve only done this for VST, VST3 and AU

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 11, 2020, 11:41pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/9 "2020-05-11T23:41:03Z")

</div>

I code signed the AU, VST, and VST3.

However, I tried individually as-well as in a one folder like you said.  
I do not know about timestamped…

---

<div class="post-metadata">

**Author:** ![jnicol](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/jnicol/32/1532_2.png) [@jnicol](https://forum.juce.com/u/jnicol)\
**Post date:** [May 11, 2020, 11:45pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/10 "2020-05-11T23:45:01Z")

</div>

You could try adding the --verbose flag to your altool command, which might give more insight into the error?

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 11, 2020, 11:47pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/11 "2020-05-11T23:47:30Z")

</div>

> [@jnicol](#):
>
> codesign -dvv

It is code signed until I zip it…  
I just checked it is properly code signed.

I’m talking to the people at Eden maybe they can help me since I do my signing with them.

I was able to start a notarizing session earlier but my package was invalid it said.

Brain bender. Thanks for the help.

---

<div class="post-metadata">

**Author:** ![yfede](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/yfede/32/506_2.png) [@yfede](https://forum.juce.com/u/yfede)\
**Post date:** [May 12, 2020, 8:38am UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/12 "2020-05-12T08:38:34Z")

</div>

> [@TypeWriterAudio](#):
>
> It is code signed until I zip it…

Do you mean that you sign your plug-in, then zip it, and when when unzipped its signature is invalid?  
If that is the case, it may be an issue with symbolic links not being restored exactly as they were, if your bundle contains some of those (also as a result of the code signing process).  
That alone would be a sufficient cause for invalidating the digital signature.

Check with a tool like Kdiff3 if the signed plug-in bundle prior to zipping is exactly equal to what comes out of the unzipping of it

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 13, 2020, 1:00am UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/13 "2020-05-13T01:00:53Z")

</div>

Apparently in February they changed warnings to be errors so everything has to be exact. I included --timestamp in my project however even after signing with a certificate from my apple developer account I am still getting this error?  
Do I have to use a Developer ID Application .cer from Xcode? If so that has no keys available.

Should I be trying this on an archive instead of a build?

Does anybody know how to get a valid Developer Certificate swell as how to timestamp?

{  
“logFormatVersion”: 1,  
“jobId”: “7a96ba85-0f25-42c4-ac6f-43910a7b513b”,  
“status”: “Invalid”,  
“statusSummary”: “Archive contains critical validation errors”,  
“statusCode”: 4000,  
“archiveFilename”: “MYPLUGIN\_signed.component.zip”,  
“uploadDate”: “2020-05-12T13:04:18Z”,  
“sha256”: “7865c45f80328bfb95082eb0301582133d4325e886bc2936b2d0bf02b6c82724”,  
“ticketContents”: null,  
“issues”: [  
{  
“severity”: “error”,  
“code”: null,  
“path”: “MYPLUGIN\_signed.component.zip/MYPLUGIN\_signed.component/Contents/MacOS/MYPLUGIN”,  
“message”: “The binary is not signed with a valid Developer ID certificate.”,  
“docUrl”: null,  
“architecture”: “x86\_64”  
},  
{  
“severity”: “error”,  
“code”: null,  
“path”: “MYPLUGIN\_signed.component.zip/MYPLUGIN\_signed.component/Contents/\_\_Pace\_Eden.bundle/Contents/MacOS/\_\_Pace\_Eden”,  
“message”: “The binary is not signed with a valid Developer ID certificate.”,  
“docUrl”: null,  
“architecture”: “x86\_64”  
},  
{  
“severity”: “error”,  
“code”: null,  
“path”: “MYPLUGIN\_signed.component.zip/MYPLUGIN\_signed.component/Contents/\_\_Pace\_Eden.bundle/Contents/MacOS/\_\_Pace\_Eden”,  
“message”: “The signature does not include a secure timestamp.”,  
“docUrl”: null,  
“architecture”: “x86\_64”  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 13, 2020, 1:03am UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/14 "2020-05-13T01:03:01Z")

</div>

I am trying to sign then notarize with one command using the Eden SDK.

---

<div class="post-metadata">

**Author:** ![mcmartin](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/mcmartin/32/7432_2.png) [@mcmartin](https://forum.juce.com/u/mcmartin)\
**Post date:** [May 13, 2020, 7:38am UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/15 "2020-05-13T07:38:43Z")

</div>

For the “secure timestamp”, you need to pass `--timestamp` (usually without any value) to `codesign` when initially signing (i.e. before notarization). See the man page of `codesign` for reference:

```auto
--timestamp [=URL]
         During signing, requests that a timestamp authority server be contacted to authenticate the time of signing. The
         server contacted is given by the URL value. If this option is given without a value, a default server provided by
         Apple is used. Note that this server may not support signatures made with identities not furnished by Apple.

```

---

<div class="post-metadata">

**Author:** ![yfede](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/yfede/32/506_2.png) [@yfede](https://forum.juce.com/u/yfede)\
**Post date:** [May 13, 2020, 8:09am UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/16 "2020-05-13T08:09:09Z")

</div>

> [@TypeWriterAudio](#):
>
> I am trying to sign then notarize with one command using the Eden SDK

I believe that, for using the EDEN SDK, you had to sign an NDA that forbids public discussions of technical details.  
While I agree that we’re not discussing sensitive aspects, I think we’re not formally allowed to talk about this here.  
**Perhaps, now that PACE owns the place, a separate section of the forum could be created for discussion of EDEN usage, with access restricted to only those accounts that also have signed the NDA?**

---

<div class="post-metadata">

**Author:** ![asimilon](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/asimilon/32/4235_2.png) [@asimilon](https://forum.juce.com/u/asimilon)\
**Post date:** [May 13, 2020, 11:48am UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/17 "2020-05-13T11:48:57Z")

</div>

> [@TypeWriterAudio](#):
>
> anybody know how to get a valid Developer Certificate

> **[Sign In - Apple](https://idmsa.apple.com/IDMSWebAuth/signin?appIdKey=891bd3417a7776362562d2197f89480a8547b108fd934911bcbea0110d07f757&path=%2Faccount%2Fresources%2Fcertificates%2Fadd&rv=1)**
>
> Sign in with your Apple ID

You will need one of each if you plan to use a standard macOS installer package :

 ![image](https://us1.discourse-cdn.com/flex026/uploads/juce/original/2X/b/bb602bc46e50550abd4218f378b77e21f2fd8459.png)

but you use the latter to sign your plugins before notarisation.

---

<div class="post-metadata">

**Author:** ![railjonrogut](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/railjonrogut/32/505_2.png) [@railjonrogut](https://forum.juce.com/u/railjonrogut)\
**Post date:** [May 13, 2020, 7:23pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/18 "2020-05-13T19:23:17Z")

</div>

Besides the PACE’s wraptool I also use DropDMG and SD Notary:

[https://c-command.com/dropdmg/](https://c-command.com/dropdmg/)

> **[SD Notary: Notarizing Made Easy](https://latenightsw.com/sd-notary-notarizing-made-easy/)**
>
> SD Notary is a utility for having apps notarized by Apple. With macOS 10.13.6, Gatekeeper is requiring notarized apps where it previously accepted simple code-signed apps. The basic process involve…

Rail

---

<div class="post-metadata">

**Author:** ![TypeWrit3r](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/typewrit3r/32/3993_2.png) [@TypeWrit3r](https://forum.juce.com/u/TypeWrit3r)\
**Post date:** [May 14, 2020, 4:45pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/19 "2020-05-14T16:45:40Z")

</div>

After testing for a few days I came up with this thanks to everyone with the resources.  
@jnicol that really helped.  
I am going to leave an exact guide here for anyone in the future wanting a straight forward guide to the entire process of notarizing. I ended up code signing with apple rather than Eden, which is a whole other bear.

---

<div class="post-metadata">

**Author:** ![jnicol](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/jnicol/32/1532_2.png) [@jnicol](https://forum.juce.com/u/jnicol)\
**Post date:** [May 14, 2020, 9:09pm UTC](https://forum.juce.com/t/notarizing-after-code-signing/39351/20 "2020-05-14T21:09:21Z")

</div>

If the process with Apple is easier than Eden, then wow. Because Apple’s process is is royal PITA.

[Next page](https://forum.juce.com/t/notarizing-after-code-signing/39351.md?page=2)
