Files
MailUI4Agents/client/harmony/build-profile.json5
JianFeeeee b2a0a42c91 docs(harmony): ★★ 推送根因定位到"**签错了证书**",不是"debug 证书不被接受"
平板复测抓到一条上一轮漏掉的华为侧日志,它把根因从推断变成实测:

    E cloudinterfaceauth/AuthService: cert finger empty, clientId: 2039846327155747840
    I PushService: push token 取不到:code=1000900010 Illegal application identity

★ `cert finger empty` = 设备报上来的是**空指纹**,不是"指纹对不上"。
  与 `bm dump` 完全吻合:appSignType=none、signatureKey=""。
  ⇒ 包里根本没有应用签名身份。

三个指纹实测对比(本机 openssl 算出):
  build-profile.json5 的 certpath → DF:21:A3:C0:…:DF:3A:37  CN=Huawei CBG Root CA G2
  .p7b 内嵌 development-cert    → FD:89:AC:53:…:FC:9D:09  CN=靳睿(…)\,Development
⇒ 工程签的是 **CA 根证书**,profile 绑的是**开发者应用证书**,两者根本不是同一张。

profile 侧其余要素已逐项排除为无关:bundle-name 对、type=debug、validity 未过期、
平板 UDID(bm get -u)逐字出现在 device-ids 里。

★★ 顺带记下走不通的那条路,免得下次重走:
  把 certpath 改成 profile 内嵌的单张 dev cert → hvigor 报
  `11013004 Profile cert must a cert chain`。
  **certpath 要的是一条链**,而那张 dev cert 的签发者
  `Huawei CBG Developer Relations CA G2` 本机没有(5 个 p7b 里都没有,
  material/ 里也没有任何证书)。
  ⇒ 给用户要材料时要说准:要**能构成链的整套**,单张 .cer 装不上;
    最省事是 DevEco 里 Project Structure → Signing Configs 直接同步签名。

服务端侧本轮复验仍正常:与 hms.go 同形(不带 scope)请求华为换到
access_token,长度 104、有效期 3600s ⇒ 断点确实只在设备侧签名。

build-profile.json5 的 certpath 保持原值并加了注释:改成单张 dev cert 会编译不过,
留着编不过的值只会连应用都装不上。
2026-10-02 00:32:21 +08:00

80 lines
3.1 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
app: {
signingConfigs: [
{
name: 'default',
type: 'HarmonyOS',
material: {
/*
* ★★ 2026-10-02 真机推送排查:**这里签的是 CA 根证书,不是应用证书**。
*
* 设备实测(平板 MRDI-W00,`bm dump`):
* "appSignType": "none" / "signatureKey": "" / "appProvisionType": "debug"
* ⇒ 包里**根本没有应用签名身份**,于是 HMS 的
* `AuthService: cert finger empty, clientId: 2039846327155747840`
* 拿不到指纹,判成 `1000900010 Illegal application identity`,
* push token 因此永远取不到(`push_tokens` 表 0 行)。
*
* 证书比对(本机实测的三个指纹):
* 本文件这个 .cer DF:21:A3:C0:…:DF:3A:37 CN=Huawei CBG Root CA G2 ← CA 根
* profile 内嵌 dev cert FD:89:AC:53:…:FC:9D:09 CN=靳睿(…)\,Development ← 应用的
* profile 的 type "debug"
* ⇒ 签的证书与 profile 绑定的**不是同一张**,这就是 "cert finger empty" 的来源。
*
* ⚠️ 曾把它改成 profile 内嵌的单张 dev cert 想试,hvigor 直接报
* `11013004 Profile cert must a cert chain` —— **certpath 要的是一条链**
* (应用证书 + 签发它的 CA),而 dev cert 的签发者
* `Huawei CBG Developer Relations CA G2` **本机没有**(5 个 p7b 里都没有)。
* ⇒ 要修好必须补齐 dev cert 的**签发链**(AGC/DevEco 后台导出的那套发布或调试证书),
* 然后把 certpath 指向那条链。在那之前这里保持原样,
* 因为改成一个编译不过的值只会连应用都装不上。
*/
certpath: '/root/.ohos/config/default_harmony_k2yruKTLaTiZOjublhUDTfveVx5uFoHqm96pwkUw=.cer',
keyAlias: 'debugKey',
keyPassword: '0000001b64d7bb074eed97bb2c6ad5ae60df2f72256b104361c3fd8c4f842eb42961fce4b712e7410dd208',
profile: '/root/.ohos/config/default_harmony_k2yruKTLaTiZOjublhUDTfveVx5uFoHqm96pwkUw=.p7b',
signAlg: 'SHA256withECDSA',
storeFile: '/root/.ohos/config/default_harmony_k2yruKTLaTiZOjublhUDTfveVx5uFoHqm96pwkUw=.p12',
storePassword: '0000001b64d7bb074eed97bb2c6ad5ae60df2f72256b104361c3fd8c4f842eb42961fce4b712e7410dd208',
},
},
],
products: [
{
name: 'default',
signingConfig: 'default',
targetSdkVersion: '6.1.0(23)',
compatibleSdkVersion: '6.1.0(23)',
runtimeOS: 'HarmonyOS',
buildOption: {
strictMode: {
caseSensitiveCheck: true,
useNormalizedOHMUrl: true,
},
},
},
],
buildModeSet: [
{
name: 'debug',
},
{
name: 'release',
},
],
},
modules: [
{
name: 'entry',
srcPath: './entry',
targets: [
{
name: 'default',
applyToProducts: [
'default',
],
},
],
},
],
}