# Collating codesign for the end?

**URL:** https://discourse.cmake.org/t/collating-codesign-for-the-end/4220
**Category:** Usage
**Created:** [October 7, 2021, 5:43am UTC](https://discourse.cmake.org/t/collating-codesign-for-the-end/4220 "2021-10-07T05:43:26Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![lundman](https://discourse.cmake.org/user_avatar/discourse.cmake.org/lundman/32/936_2.png) [@lundman](https://discourse.cmake.org/u/lundman)
#### Post date: [October 7, 2021, 5:43am UTC](https://discourse.cmake.org/t/collating-codesign-for-the-end/4220/1 "2021-10-07T05:43:26Z")

</div>

Currently I codesign executables with

```auto
function(um_add_executable name)
	add_executable(${ARGV})
	add_custom_command(
		TARGET ${name}
		POST_BUILD
		COMMAND "${SIGNTOOL_PROGRAM}"

```

Which is fine and works. But since each codesign is a separate process, I have to enter the PIN each time, for each executable in the projected.  
Curious if there was an easy/smart way to collect all executables, and at the very end of the build, codesign them as one go - and maybe I only need to enter the PIN once?

---

<div class="post-metadata">

### Author: ![ben.boeckel](https://discourse.cmake.org/letter_avatar_proxy/v4/letter/b/ea5d25/32.png) [@ben.boeckel](https://discourse.cmake.org/u/ben.boeckel)
#### Post date: [October 8, 2021, 12:44am UTC](https://discourse.cmake.org/t/collating-codesign-for-the-end/4220/2 "2021-10-08T00:44:51Z")

</div>

I don’t think that would work as nicely since the build tool (`make` or `ninja`) would have no way to know if it needs to be run. AFAICT, `codesign` modifies binaries in-place, so the rule that signs the code could not depend on the binary since it will modify it on its own.

I would say that signing should be left to be an installation step or to bundle it with a step that copies the binary from the build and signs the copy (so that there’s no dependency loop). Either of these solutions _should_ be able to do batching (up to what `codesign` supports for batching).
