Hi,
after spending a lot of time and energy in getting all the bits
correctly assembled we now think we have a properly[1] signed OS X
bundle that should pass the Gatekeeper test:
https://people.torproject.org/~gk/testbuilds/torbrowser-signing-test.dmghttps://people.torproject.org/~gk/testbuilds/torbrowser-signing-test.dmg.asc
If you happen to own an OS X with Gatekeeper enabled, please give it a
try and report back if things are working fine or a broken.
Thanks,
Georg
[1] There is one caveat: the bundle is not timestamped at the moment.
But that should not impact the validity of the signature until the
certificate is expired.