Skip to content

Add APPX_SIP_CLIENT_DATA and SIGNER_SIGN_EX2/EX3_PARAMS - #2353

Open
Victor Irzak (virzak) wants to merge 1 commit into
microsoft:mainfrom
virzak:appx-sip-client-data
Open

Victor Irzak (virzak) wants to merge 1 commit into
microsoft:mainfrom
virzak:appx-sip-client-data

Conversation

@virzak

@virzak Victor Irzak (virzak) commented Oct 3, 2026 •

Copy link
Copy Markdown

Fixes #2307

Signing an app package (.appx/.msix and bundles) with SignerSignEx2 / SignerSignEx3 requires passing an APPX_SIP_CLIENT_DATA through pSipData, which points to a SIGNER_SIGN_EX2_PARAMS (or SIGNER_SIGN_EX3_PARAMS for SignerSignEx3). None of these are in the Windows SDK headers, so CsWin32 users have to declare them by hand (for example, AzureSignTool's Interop/mssign32.cs).

Changes

  • mssign.h (AdditionalHeaders and its RecompiledIdlHeaders/um copy): add the three structs.
    • SIGNER_SIGN_EX2_PARAMS and APPX_SIP_CLIENT_DATA follow How to programmatically sign an app package.
    • SIGNER_SIGN_EX3_PARAMS is undocumented; its layout matches the one AzureSignTool uses in production against mssign32.dll. The callback field is typed PSIGNER_DIGEST_SIGN_INFO, matching SignerSignEx3's pDigestSignInfo parameter.
    • pCryptoPolicy is typed PCERT_STRONG_SIGN_PARA in both, matching the function signatures.
  • enums.json: apply SIGNER_SIGN_FLAGS and SIGNER_TIMESTAMP_FLAGS to the dwFlags / dwTimestampFlags fields of both param structs.

Validation

  • ./DoAll.ps1 -ExcludePackages -ExcludeSamples builds cleanly. The winmd diff shows APPX_SIP_CLIENT_DATA, SIGNER_SIGN_EX2_PARAMS and SIGNER_SIGN_EX3_PARAMS added to Windows.Win32.Security.Cryptography, with the flag enums applied to their fields.
  • I also compiled the header with MSVC on x64 and x86, with static_asserts on struct sizes and the offset of the callback field.

🤖 Generated with Claude Code

Signing app packages with SignerSignEx2/SignerSignEx3 requires passing an
APPX_SIP_CLIENT_DATA through pSipData, which points to a
SIGNER_SIGN_EX2_PARAMS (or SIGNER_SIGN_EX3_PARAMS for SignerSignEx3).
None of these are declared in the Windows SDK headers.

Also apply SIGNER_SIGN_FLAGS and SIGNER_TIMESTAMP_FLAGS to the matching
struct fields.

Fixes microsoft#2307

Generated with Claude Code
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add APPX_SIP_CLIENT_DATA, SIGNER_SIGN_EX2_PARAMS and SIGNER_SIGN_EX3_PARAMS for app package signing

1 participant