Tracking issue for the remaining desktop security items (all code is merged; these need team-side credentials). Companion to docs/PHASE4_PLAN.md Track A.
Checklist
Note: pinning is fail-closed by design — the window never loads the gateway on pin mismatch (desktop/main.js). Windows installers remain unsigned for beta; OV cert optional later.
This was requested as a Jira ticket; Jira is not connected to this workspace, so it is tracked here (GitHub issues #463–#466 precedent).
Tracking issue for the remaining desktop security items (all code is merged; these need team-side credentials). Companion to docs/PHASE4_PLAN.md Track A.
Checklist
.p12(docs/SIGNING_GUIDE.md §2)MAC_CERT_BASE64,MAC_CERT_PASSWORD,APPLE_ID,APPLE_APP_SPECIFIC_PASSWORD,APPLE_TEAM_IDxcrun notarytool historyshows Accepted for the first release buildCIPHERTUBE_CERT_PINsecret set → fail-closed pinning active in release buildsspctl --assesspasses on the signed.appNote: pinning is fail-closed by design — the window never loads the gateway on pin mismatch (desktop/main.js). Windows installers remain unsigned for beta; OV cert optional later.
This was requested as a Jira ticket; Jira is not connected to this workspace, so it is tracked here (GitHub issues #463–#466 precedent).