docs(harmony): ★★ 推送根因定位到"**签错了证书**",不是"debug 证书不被接受"
平板复测抓到一条上一轮漏掉的华为侧日志,它把根因从推断变成实测:
E cloudinterfaceauth/AuthService: cert finger empty, clientId: 2039846327155747840
I PushService: push token 取不到:code=1000900010 Illegal application identity
★ `cert finger empty` = 设备报上来的是**空指纹**,不是"指纹对不上"。
与 `bm dump` 完全吻合:appSignType=none、signatureKey=""。
⇒ 包里根本没有应用签名身份。
三个指纹实测对比(本机 openssl 算出):
build-profile.json5 的 certpath → DF:21:A3:C0:…:DF:3A:37 CN=Huawei CBG Root CA G2
.p7b 内嵌 development-cert → FD:89:AC:53:…:FC:9D:09 CN=靳睿(…)\,Development
⇒ 工程签的是 **CA 根证书**,profile 绑的是**开发者应用证书**,两者根本不是同一张。
profile 侧其余要素已逐项排除为无关:bundle-name 对、type=debug、validity 未过期、
平板 UDID(bm get -u)逐字出现在 device-ids 里。
★★ 顺带记下走不通的那条路,免得下次重走:
把 certpath 改成 profile 内嵌的单张 dev cert → hvigor 报
`11013004 Profile cert must a cert chain`。
**certpath 要的是一条链**,而那张 dev cert 的签发者
`Huawei CBG Developer Relations CA G2` 本机没有(5 个 p7b 里都没有,
material/ 里也没有任何证书)。
⇒ 给用户要材料时要说准:要**能构成链的整套**,单张 .cer 装不上;
最省事是 DevEco 里 Project Structure → Signing Configs 直接同步签名。
服务端侧本轮复验仍正常:与 hms.go 同形(不带 scope)请求华为换到
access_token,长度 104、有效期 3600s ⇒ 断点确实只在设备侧签名。
build-profile.json5 的 certpath 保持原值并加了注释:改成单张 dev cert 会编译不过,
留着编不过的值只会连应用都装不上。
This commit is contained in:
@ -5,6 +5,30 @@
|
||||
name: 'default',
|
||||
type: 'HarmonyOS',
|
||||
material: {
|
||||
/*
|
||||
* ★★ 2026-10-02 真机推送排查:**这里签的是 CA 根证书,不是应用证书**。
|
||||
*
|
||||
* 设备实测(平板 MRDI-W00,`bm dump`):
|
||||
* "appSignType": "none" / "signatureKey": "" / "appProvisionType": "debug"
|
||||
* ⇒ 包里**根本没有应用签名身份**,于是 HMS 的
|
||||
* `AuthService: cert finger empty, clientId: 2039846327155747840`
|
||||
* 拿不到指纹,判成 `1000900010 Illegal application identity`,
|
||||
* push token 因此永远取不到(`push_tokens` 表 0 行)。
|
||||
*
|
||||
* 证书比对(本机实测的三个指纹):
|
||||
* 本文件这个 .cer DF:21:A3:C0:…:DF:3A:37 CN=Huawei CBG Root CA G2 ← CA 根
|
||||
* profile 内嵌 dev cert FD:89:AC:53:…:FC:9D:09 CN=靳睿(…)\,Development ← 应用的
|
||||
* profile 的 type "debug"
|
||||
* ⇒ 签的证书与 profile 绑定的**不是同一张**,这就是 "cert finger empty" 的来源。
|
||||
*
|
||||
* ⚠️ 曾把它改成 profile 内嵌的单张 dev cert 想试,hvigor 直接报
|
||||
* `11013004 Profile cert must a cert chain` —— **certpath 要的是一条链**
|
||||
* (应用证书 + 签发它的 CA),而 dev cert 的签发者
|
||||
* `Huawei CBG Developer Relations CA G2` **本机没有**(5 个 p7b 里都没有)。
|
||||
* ⇒ 要修好必须补齐 dev cert 的**签发链**(AGC/DevEco 后台导出的那套发布或调试证书),
|
||||
* 然后把 certpath 指向那条链。在那之前这里保持原样,
|
||||
* 因为改成一个编译不过的值只会连应用都装不上。
|
||||
*/
|
||||
certpath: '/root/.ohos/config/default_harmony_k2yruKTLaTiZOjublhUDTfveVx5uFoHqm96pwkUw=.cer',
|
||||
keyAlias: 'debugKey',
|
||||
keyPassword: '0000001b64d7bb074eed97bb2c6ad5ae60df2f72256b104361c3fd8c4f842eb42961fce4b712e7410dd208',
|
||||
|
||||
Reference in New Issue
Block a user