macOS 22.1.6 bareos-fd not signed

40 views
Skip to first unread message

Joshua Myles

unread,
Sep 16, 2024, 3:32:50 PM9/16/24
to bareos-users
Hi,

I wanted to raise this here before opening a Github issue in case it's a simple thing (I'm not a macOS expert).

We use an MDM system for our macOS desktops, so need to update the policies every time we upgrade Bareos on a client (FD). I just upgraded one from 22.1.5 to 22.1.6, and when we went to look at the new bareos-fd to update the policy signature we found:

% codesign --display --requirements - /usr/local/bareos/sbin/bareos-fd
/usr/local/bareos/sbin/bareos-fd: code object is not signed at all
%

Should this not be signed or am I missing something? This is from the bareos-22.1.6.pkg subscription package.

Thanks,

Josh

Andreas Rogge

unread,
Sep 17, 2024, 7:53:10 AM9/17/24
to bareos...@googlegroups.com
Hi Joshua,

we do sign the DEBs, RPMs and FreeBSD packages with a GPG key and we
sign the Windows installer with a Code Signing certificate.

I don't think we ever signed the MacOS packages and I'm pretty sure we
don't do individual signatures on files contained in the packages.
Could you check if 22.1.5 (or any other package) was actually signed?

Do have a specific requirement for things to be signed? If that's the
case, we can probably discuss your requirements and see what we can do.

Best Regards,
Andreas


Am 16.09.24 um 21:32 schrieb Joshua Myles:
> --
> You received this message because you are subscribed to the Google
> Groups "bareos-users" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to bareos-users...@googlegroups.com
> <mailto:bareos-users...@googlegroups.com>.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/bareos-users/4fcc0439-6ec7-4ee5-8240-474ae8bdcc11n%40googlegroups.com <https://groups.google.com/d/msgid/bareos-users/4fcc0439-6ec7-4ee5-8240-474ae8bdcc11n%40googlegroups.com?utm_medium=email&utm_source=footer>.

--
Andreas Rogge andrea...@bareos.com
Bareos GmbH & Co. KG Phone: +49 221-630693-86
http://www.bareos.com

Sitz der Gesellschaft: Köln | Amtsgericht Köln: HRA 29646
Komplementär: Bareos Verwaltungs-GmbH
Geschäftsführer: Stephan Dühr, Jörg Steffens, Philipp Storz
OpenPGP_signature.asc
Message has been deleted
Message has been deleted

Joshua Myles

unread,
Sep 18, 2024, 3:52:58 AM9/18/24
to bareos-users
Hmm, seems like my reply disappeared. Anyway, this is from the 22.1.5 subscription package:

% codesign --display --requirements - /usr/local/bareos/sbin/bareos-fd
Executable=/usr/local/bareos/sbin/bareos-fd
# designated => cdhash H"65a23b668a41c7f2d56f03d47bf6e517877090e8"
%


As far as I'm aware they've been signed for the last several versions since we've had the MDM policy in place for at least that long.

Josh

Joshua Myles

unread,
Sep 18, 2024, 3:52:58 AM9/18/24
to bareos-users
22.1.5, subscription package:

% codesign --display --requirements - /usr/local/bareos/sbin/bareos-fd
Executable=/usr/local/bareos/sbin/bareos-fd
# designated => cdhash H"65a23b668a41c7f2d56f03d47bf6e517877090e8"
%


I think the preference is that they be signed but am talking to our macOS team to see what they think.

Josh

On Tuesday, September 17, 2024 at 7:53:10 AM UTC-4 Andreas Rogge wrote:

Joshua Myles

unread,
Sep 18, 2024, 7:45:06 AM9/18/24
to bareos-users
Continuing this in https://github.com/bareos/bareos/discussions/1959 at Andreas' suggestion.

Josh
Reply all
Reply to author
Forward
0 new messages