8 ms·
The deprecation of SHA-1 is an issue, though. Timestamps after January 1, 2016 must be SHA-256, and SHA-1 signed files will be blocked after January 1, 2017. Ho
by nhebb 10y ago
The deprecation of SHA-1 is an issue, though. Timestamps after January 1, 2016 must be SHA-256, and SHA-1 signed files will be blocked after January 1, 2017. However, Microsoft has blogged that they may block them starting this June. Pre-Win7 systems don't recognize SHA-256, so you have to dual sign the files if you want backward compatibility. Except, MSI files can't be dual signed. I'm also finding that more Win7 users than I would expect don't have the proper updates, so their systems don't recognize SHA-256.
In short, it's a mess.
- yuhong 10y agoYou can sign with a SHA1 hash but a SHA256 certificate, and have it work on unpatched Win7 and even Vista SP2 with a hotfix installed (to fix a minor problem).