# DIfficult to install Slicer because the installer is not signed

**URL:** <https://discourse.slicer.org/t/difficult-to-install-slicer-because-the-installer-is-not-signed/238>\
**Category:** Development\
**Created:** [May 2, 2017, 2:57am UTC](https://discourse.slicer.org/t/difficult-to-install-slicer-because-the-installer-is-not-signed/238 "2017-05-02T02:57:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)\
**Post date:** [May 2, 2017, 2:57am UTC](https://discourse.slicer.org/t/difficult-to-install-slicer-because-the-installer-is-not-signed/238/1 "2017-05-02T02:57:48Z")

</div>

It is getting more and more difficult to install Slicer’s unsigned installation package.

On Windows, the user has to click through a series of dialog boxes explaining how unsafe this downloaded application is and recently SmartFilter scans started to take several minutes (the user just waiting for the SmartFilter dialog to go away, it’s not clear what’s happening).

The situation is getting worse on Mac, too, as reported by @Fedorov here: [Multiple startup errors and no SimpleITK in May 1 nightly on mac](https://discourse.slicer.org/t/multiple-startup-errors-and-no-simpleitk-in-may-1-nightly-on-mac/231/8).

@jcfr you worked on this in the past, can you summarize how far you got and what would need to be done to get the installation packages signed?

---

<div class="post-metadata">

**Author:** ![jcfr](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/jcfr/32/17825_2.png) [@jcfr](https://discourse.slicer.org/u/jcfr)\
**Post date:** [May 2, 2017, 3:05am UTC](https://discourse.slicer.org/t/difficult-to-install-slicer-because-the-installer-is-not-signed/238/2 "2017-05-02T03:05:39Z")

</div>

> [@lassoan](#):
>
> you worked on this in the past, can you summarize how far you got and what would need to be done to get the installation packages signed?

### windows

it is quite “straight forward” to sign the installer at least, see [Documentation/Nightly/Developers/Windows Code Signing - Slicer Wiki](https://www.slicer.org/wiki/Documentation/Nightly/Developers/Windows_Code_Signing)

We have available certificate(s) (we already use them for signing the stable release). I will check internally how we can automate signing of the nightly installers.

### MacOSX,

We also have the process documented here: [Documentation/Nightly/Developers/Mac OS X Code Signing - Slicer Wiki](https://www.slicer.org/wiki/Documentation/Nightly/Developers/Mac_OS_X_Code_Signing)

For this one, we need to update the packaging system to be more closely integrated with the signing process.

Also, we have certificate available (we are member of the developer program). I will check internally and report back with a timeline.

---

<div class="post-metadata">

**Author:** ![lassoan](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/lassoan/32/13_2.png) [@lassoan](https://discourse.slicer.org/u/lassoan)\
**Post date:** [May 2, 2017, 4:13pm UTC](https://discourse.slicer.org/t/difficult-to-install-slicer-because-the-installer-is-not-signed/238/3 "2017-05-02T16:13:38Z")

</div>

Thanks for the information, it sounds very promising!

---

<div class="post-metadata">

**Author:** ![jcfr](https://sea2.discourse-cdn.com/flex002/user_avatar/discourse.slicer.org/jcfr/32/17825_2.png) [@jcfr](https://discourse.slicer.org/u/jcfr)\
**Post date:** [May 8, 2017, 4:04pm UTC](https://discourse.slicer.org/t/difficult-to-install-slicer-because-the-installer-is-not-signed/238/4 "2017-05-08T16:04:20Z")

</div>

To follow up on this, internally at Kitware we are currently discussing how to solve the issue across our platforms. While I don’t yet have a timeline, I can tell that we are making progress.

The idea will be to have decoupled components including “signing systems” (e.g windows system for installer signing, MacOSX system for dmg signing, Linux based GPG signing for source distribution, …) and a “distributions depot” system (probably an internal SFTP server).
