Fix keychain add-certificates
on macOS 15
#428
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
On macOS 15.0
security import -f pkcs12
does not accept unencrypted PKCS#12 containers that are generated by OpenSSL. The command terminates with exist code 1 and emits an error:% security import certificate.p12 -f pkcs12 -k my-keychain.keychain-db -P "" -T /usr/bin/codesign -T /usr/bin/productsign security: SecKeychainItemImport: Unable to decode the provided data.
The very same certificate can be still imported when
-f
switch value is changed toopenssl
:% security import certificate.p12 -f openssl -k my-keychain.keychain-db -P "" -T /usr/bin/codesign -T /usr/bin/productsign 1 key imported. 1 certificate imported.
Alter action
keychain add-certificates
to use attempt certificate import withopenssl
format if initial import withpkcs12
format fails such that error message containsUnable to decode the provided data
.Updated actions:
keychain add-certificates