ADT error with comodo code signing certificate

Hello

I am signing an AIR application with a Comodo code signing certificate.

SHA-256 with RSA encryption

-Java 1.8 (same problem with 1.6)

-AIR 15 (same problem with older versions)

My order:

java -jar -Xmx1024m /data/sdk/AIRSDK_Compiler15/lib/adt.jar  -sign -storetype pkcs12 -storepass ******* -keystore cert/air-distrib.p12 bin-release/TestCert.airi bin-release/TestCert.air

I get the following error:

Exception in thread "main" java.lang.OutOfMemoryError: Java heap space
    at java.util.Arrays.copyOf(Arrays.java:3181)
    at java.util.ArrayList.grow(ArrayList.java:261)
    at java.util.ArrayList.ensureExplicitCapacity(ArrayList.java:235)
    at java.util.ArrayList.ensureCapacityInternal(ArrayList.java:227)
    at java.util.ArrayList.add(ArrayList.java:458)
    at sun.security.pkcs12.PKCS12KeyStore.engineLoad(PKCS12KeyStore.java:2026)
    at java.security.KeyStore.load(KeyStore.java:1433)
    at com.adobe.ucf.UCF.processSigningOptions(UCF.java:313)
    at com.adobe.ucf.UCF.parseSigningOptions(UCF.java:298)
    at com.adobe.air.ADT.parseSign(ADT.java:1589)
    at com.adobe.air.ADT.parseArgsAndGo(ADT.java:598)
    at com.adobe.air.ADT.run(ADT.java:435)
    at com.adobe.air.ADT.main(ADT.java:485)

When I increase java memory to 8 GB, java uses 6 GB and do not stop... (nothing after 20 minutes...)

Any idea?

Problem of ADT or cert? Others?

THX.

Jonas

Yes!
The certificate was generated in firefox...
Import it in IE and regenerate the certificate solved the problem

Jonas

Tags: Adobe AIR

Similar Questions

  • Code signing certificate renewal problem

    We recently renewed our Verisign code signing certificate, only to find out that it breaks the process of automatic update with the notorious error "this application cannot be installed because this installer has been misconfigured." We were able to make it work using the ADT-migrate command. It's all good and wonderful. But there are two issues I see. First of all, there is a limit of 180 days, beyond which users is no longer updated. Then, when our certificate gets renewed next year, we could be stuck in a situation where we have to choose which users get to update and who are orphaned and are forced to uninstall/re-install.

    Also, how much of this we have to live with the pain becomes a function of how long a certificate we are willing to pay for. If we are a small company of doubling money for a year 3 certificate could be painless. Why should that be a factor? Why is it not simple to renew the same certificate and have facilities at the beginning of time be well with him?

    Maybe there's something about the renewal process which is not fair. However, when I renewed my cert of Verisign that their process fairly well got me to keep everything about the renewed cert, identical to the original, otherwise it would not be a "renewal."

    If there is something arcane we miss them I'd appreciate it more for what it is. It shouldn't be this difficult.

    Thank you

    Kevin

    Hey Kevin,

    I asked around and learned that the process you describe is "as planned."  However, there are strategies to minimize the disadvantages.

    For more information, please see the following documents:

    AIR 2.6 periods Migration Signature Grace

    Update strategies for changing certificates

    Regularly update your Applications

    Code singing in Adobe AIR

    Hope this helps,

    Chris

  • How to fix the error with the code: 0xe7210001 failed to load powrprof, object: cls

    Hello

    Dose anyone know how to fix the error with the code: 0xe7210001, message: unable to load powrprof, object: CLSD-no-it is found;
    OR: Fingerprintsoftware OR error: replicas THotkey.exe message window and the computer freezes

    Maleware scanned and virus, also in safe mode, found no infection, reinstalled driver fingerprint, but nothing has changed.

    grateful for the help!

    Hello

    > message: unable to load powrprof, object: CLSD-no-it is found;
    In my view, this would mean that there is a problem with Toshiba Power Saver
    What laptop Toshiba, you have exactly?

    Maybe reinstall Power Saver could help. You can find it on the official website of Toshiba.

  • Error with the Code of execution of RIM signing Key (RRT)

    Hello

    I changed my request but,

    When I try to run my program, I get an error stating:

    Error at startup MyProgram: Module "MyProgram" to be signed with the RIM Code Signing Key (RRT) DURATION.

    I can help with this question.

    Additional information:

    BlackBerry JDE 4.5.0

    JDK 1.6.0

    Device: BlackBerry 8320

    Thank you

    I do not understand your question.

    Any program accessing a secure API requires the signatures to run on the device (it's OK on the Simulator). They keys are available from the RIM for $20.

    Once you have the key, you can sign all applications you develop for the platform of BB.

    You can order the keys here:

    http://NA.BlackBerry.com/eng/developers/javaappdev/codekeys.jsp

  • Default ASA code signing certificate has expired

    Hello. I get a certificate warning expired with different versions and ASA models when you use SSL VPN. When I look at the certificate (see file attachment), it shows that it is own Cisco certificate acquired code signing from Thawte. Everyone has noticed this in the last few weeks? How can I fix it or is it solved in a future version of the ASA? BR, Eero Laaksonen

    EERO,

    You can easily change the cert:

    http://www.Cisco.com/en/us/docs/security/ASA/asa84/command/reference/JK.html#wp1597730

    Just please make sure that you are running a recent 8.0.5 + revision of software or the 8.2.5+.

    Marcin

  • Safari no longer works with SSL self-signed certificates?

    With the last Safari (9.0.3) on OS X (running 10.11.3) and iOS (9.2.1) operating system, I can no longer connect to sites that use self-signed SSL certificates. Previously, I was warned that the site certificate was not "valid", but given the opportunity to continue anyway. This is the behavior I want to come back. It still works fine in Chrome, Firefox. but now just Safari gives me an error "Safari can't open the Page" as it would if it could not reach the server. Specifically, it says "Safari can't open the page https://myselfsignedhost.com because Safari is unable to establish a connection to the server myselfsignedhost.com.

    It does not give me the opportunity to inspect the certificate, add the certificate to my keychain, trust the cert, ignore the warning once or anything else that would be useful... He's just pretending like it can't connect. Am I missing something? How to restore old functionality? This 'bug' makes safari completely useless for me.

    OK, some info... This seems to apply only to SOME sites with self signed SSL CERT... The only obvious thing I can think is that maybe it applies to sites where the SSL certificate when the page was first loaded?

    If I open a new window private, I can access the page without problem. If I open a new standard, I can also open the page, until I quit safari. Once I left, it stops loading with the same error...

    If I manually add the SSL certificate to my keychain as being approved, the page also works... There may be a cache of certificate somewhere that is out of date?

  • Hello! I tried to activate Adobe audition, but it happens that there was an error with the code 24:24! He does not think I write to activate the code number! What should I do?

    can someone help me con el problema? El codigo error not already appear y he intentado several times call por telefono pero no me han dado razon!

    Respond to problems of activacion y creation

  • Signature of a package with the signing of code .pfx certificate

    Hello

    I got a code signing certificate (.pfx) of GlobalSign and tried to connect my extension package.

    I used the tool of ZXPSignCmd and got the following response:

    Cannot generate a valid certificate chain. Please ensure that all certificates are included in the certificate file.

    The necessary chain of certificates is installed on my system (Windows 7):

    My code signing certificate,

    GlobalSign signed my certificate

    and the root certificate GlobalSign who signed it.

    The release of OpenSSL info to the certificate seems good too:

    Iteration of MAC 2000

    MAC verified OK

    Data of the PKCS7

    Keeled Keybag: pbeWithSHA1And3-KeyTripleDES-CBC, iteration 2000

    The PKCS7 figures: pbeWithSHA1And40BitRC2-CBC, iteration 2000

    Bag of certificate

    Bag of certificate

    Bag of certificate

    Signature however other files with the Windows SDK Signtool works and translates a string of correct certificate (visible in the details of the file).

    No idea what I could do wrong?

    Concerning

    Philipp

    Interestingly, the internal order of the certificates is really important. I reorganized the sections of certificate in my PEM file and converted it into a PKCS12 and now it works.

    I also tried the export of certificate through Firefox by following the instructions posted OMFguy2. It worked also.

    I took a peek in a version of the Mozilla certificate PEM, and he showed the same order of certificate section as my PEM adapted. Only the position of the private key part was different, that doesn't seem to be a problem.

    So, Microsoft seems to export the certificates in the following order:

    Personal Certificates-> certificate-> GlobalSign Root of GlobalSign Code signing certificate

    While Mozilla and my customized order are:

    GlobalSign Root certificate-certificate-personal of GlobalSign Code signing certificate > >

  • You can code sign an extension of CS with a PFX certificate

    I generated a PFX society Code signing certificate and I want to apply it to an Extension of CS I create, but in the export in Flash Builder Wizard, I cannot use a certificate P12. Is it possible to use a PFX? Yes, how?

    Thank you

    Stephen

    Hello

    I managed to install it, I had to install the PFX certificate, then export is like a P12 by Mozilla. Works now, thanks.

  • Cannot find the file .csi for code signing

    I'm new to the development for a Blackberry. I get the following error message when you try to build an application that uses a persistent store.

    WARNING! : reference to the class: net.rim.device.api.system.PersistentObject requires the signature with the key: RIM API implementation

    I found that I'm supposed to have a .csi file from when I registered with the area of the developer, but I'm not. Can I request a new one or what?

    Thank you

    Jason

    You can buy rim, code signing certificates.

    The process details are here: http://na.blackberry.com/eng/developers/javaappdev/codekeys.jsp

    Form of payment etc. is here: https://www.blackberry.com/SignedKeys/

    Once you have paid and submitted your application, it takes a few weeks to receive the keys. If you use eclipse, you can then install the keys in your IDE.

  • Code sign VISA raw driver USB for Windows 8

    Hi guys,.

    I wrote a LabVIEW program that communicates with a measuring using NI-VISA (class raw USB) USB device.
    With the development of Driver NI-VISA Wizard, I created two .inf files of drivers (for XP/2000 and 7/Vista).
    It works like a charm on my computer (Windows 7, 64-bit) and on the computers running Windows XP and 32-bit versions of Windows Vista and 7.
    I also have to work on 64 bit versions of Windows Vista and 7 using "disable driver signature enforcement" before installing the driver.
    Once the driver is installed, it is listed under "devices USB of NI-VISA" in the Windows Device Manager. After that I can reactivate the driver signature enforcement, the unit will continue to work, even after a reboot.

    Alas, in the 64-bit version of Windows 8 is not as simple as that. Yes, you can temporarily disable driver signing enforcement, but not on computers that use 'secure boot' or UEFI.
    I know that there are ways to disable booting UEFI's secure, but I don't want that on our customers computers. It seems wrong, and could introduce a large number of security problems.

    The next logical step would be to sign the device driver. Our company has a valid kernel mode code signing certificate and we signed the other drivers with it in the past.
    The problem is that I don't know how to sign my device in the NI-VISA database driver. According to the .inf file it uses WinUSB.sys, a Microsoft USB generic driver (part of the Windows Driver Kit, I think).
    Winusb.sys is already signed by Microsoft and that I could replace the signature, but that probably won't work without some tweaking inf and generate a new catalog file.

    Can someone please give me some pointers on where to start? As a reference, I have attached one of the inf files for this post. This inf file works on Windows Vista and 7.

    It is even possible to create a signed driver based on NI-VISA raw?

    Thanks in advance for your help.

    Paul

    Here's a knockout who described workaround.

    http://digital.NI.com/public.nsf/allkb/36DB8D6AC385052786257A940066A421

    What you have written, you need to generate a catalog (.cat) of the inf file (as described in step 1 of the KB) and then sign the .cat with your certificate file, the same way you would sign your other components. The inf and CAT are always distributed together. The inf file contains information about the cat file that has the signature, and the cat file contains the signature information. Since you have already been distributing the components signed with your own certificate, I'm sure you can understand the process, but please let us know if you have any other questions.

    Thank you

    Pankaj

  • Problem with WebInspector: error: Code signing request failed car-development-Application Mode in the East of the demo is present and is not set [false].

    Hi, I have a problem running the webinspector on my dev alpha.

    Whenever I have create bar folder with the d flag, and then run the signature tool, I got the error message:

    Error: Code signing of the petition failed because Application-Development-Mode demo
    is is present and not set [false].

    How to solve this problem? If I generate the .bar without the flag - d, can I sign and execute on the device, but without web Inspector

    I found the error

    I just had to use the indicator g in bbwp and set my password

    and not reuse bbwp and then the signing tool

  • Self-signed certificate installed successfully but with VR error device

    HI gurus,

    I'm in the middle of the upgrade of RS 5 5.1 RS for replication of vSphere.

    I'm trying to install and register the device VR 5.1.

    On the configuration tab I filled out the Info: and tried to produce the certificate and start the service.

    It comes up with the following msg.

    Self-signed certificate installed successfully.

    WARNING: Bad service state: execv() arg 2 must contain only strings.

    The info I have completed are as follows:

    VRM Host: ip address of host vrm

    Name of the Site of VRM: virtual site of DR (FQDN) appliance

    vCenter Server Address: address of the server vCenter DR FQDN

    vCenter Server Port: 80

    vCenter Server Admin Mail: e-mail administrators

    Thanks in advance!

    Here's your answer...

    Edit the/etc/sysconfig/network/config file.

    Find this line:

    NETCONFIG_DNS_STATIC_SERVERS = «»

    Change the line and put a DNS server IP address in quotes.

    Restart your device and try again.

    Edit: Still one thing, make sure that you deploy the version of the appliance corresponds to your version of vCenter. vCenter Server 5.5 uses the replication device 5.5, 5.1 VC uses 5.1 etc.

  • receiving the OCSP signing certificate valid error in the OCSP response;

    From 08:00 this morning, I started getting the following: valid OCSP signing certificate in OCSP response. (Error code: sec_error_ocsp_invalid_signing_cert) when you try to load any page on FANFICTION.NET; before that time, I was actively looking at Web site.

    This problem occurs always from 10:43 AM EDT despite the posts here saying that this is resolved. Features of the site very well with Chrome and IE.

    I use the version of 31.0 Firefox on a laptop Windows 8.1

    The question seems not himself have resolved to our site this morning. Don't know exactly what has changed, but for what it's worth, we are hosted on Amazon EC2, so maybe they have updated something.

  • Cannot use jar with icon files gif and self signed certificate files (Exception in thread "AWT-EventQueue-3" java.lang.NoClassDefFoundError: oracle/ewt/laf/basic/SelColorChange)

    Hi all.

    I use Forms 11 g 11.1.2.1 and updating JRE 7 45.

    I have create a jar file containing gif icons files using this procedure:

    (1) create the jar file:

    set path = % path %; C:\Oracle\Middleware\Oracle_FRHome1\jdk\bin (my ORACLE_HOME/jdk)

    jar - cvf webfigolos.jar *.gif

    (2) self sign the file:

    c:\Oracle\Middleware\asinst_1\bin > sign_webutil.bat c:\Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar

    Jars is signed but with a warning:

    Generate a signature key certificate aaosa2015 = auto...

    keytool error: java.lang.Exception: key pair not generated, al alias < aaosa2015 >

    loan is

    .

    There are errors or warnings while generating a self signed certificate. Pleas

    e revisiting.

    .

    Backup as c: C:\Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar

    \Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar.old...

    1 file (s) copied.

    Signature using ke c:\Oracle\Middleware\Oracle_FRHome1\forms\java\webfigoicons.jar

    y = aaosa2015...

    .. own made.

    But I can use this file. The application crashes and get this error from the java console:

    network: connection http://myluism-pc:7001/forms/lservlet; jsessionid = p98GTL5Fh6XnQcykySBhLWq2823HwHlPGZ16TYHVv93006N4mmdl!-947562687 with proxy = LIVE

    network: connection http://myluism-PC:7001 / with proxy = LIVE

    Exception in thread "AWT-EventQueue-3" java.lang.NoClassDefFoundError: oracle/ewt/laf/basic/SelColorChange

    at oracle.ewt.laf.oracle.OracleTreeUI.createItemPainter (unknown Source)

    at oracle.ewt.laf.basic.BasicTreeUI._getItemPainter (unknown Source)

    at oracle.ewt.laf.basic.BasicTreeUI.getItemPainter (unknown Source)

    at oracle.ewt.dTree.DTreeBaseItem.getSize (unknown Source)

    at oracle.ewt.dTree.DTree.paintCanvasInterior (unknown Source)

    at oracle.ewt.EwtComponent.paintInterior (unknown Source)

    at oracle.ewt.lwAWT.SharedPainter._paintInterior (unknown Source)

    at oracle.ewt.lwAWT.SharedPainter.paintExtents (unknown Source)

    at oracle.ewt.lwAWT.LWComponent._paintComponent (unknown Source)

    at oracle.ewt.lwAWT.LWComponent.paint (unknown Source)

    at oracle.ewt.EwtComponent.paint (unknown Source)

    at oracle.ewt.lwAWT.SharedPainter.paintExtents (unknown Source)

    at oracle.ewt.lwAWT.LWComponent._paintComponent (unknown Source)

    This used to be a very simple procedure, but it has stopped working...!

    Don't know if the jar file is well born, or if it is corrupt.

    I can't start my application.

    Help, please!

    Best regards, Luis.

    Try again with the JRE 7 10 update, I get a problem with the update of JRE 7 45, but when I tried the update of JRE 7 10, it works fine.

    For the objective test, disable the check

    Java Panel-> advance-> mixed Code-> disable verification (unchecked)

Maybe you are looking for