4 ms·
I think a proper EV should not show any warning at all. The issue here is using SHA1 instead of SHA256, not sure why op would do this. SHA1 signing was deprecat
by mnkypete 8y ago
I think a proper EV should not show any warning at all. The issue here is using SHA1 instead of SHA256, not sure why op would do this. SHA1 signing was deprecated..
https://www.globalsign.com/en/blog/microsoft-announces-updates-sha-1-code-signing-policy/ https://www.globalsign.com/en/blog/microsoft-announces-updat...
- abawany 8y agoOne reason is that if signing via the Mono Framework, the only signing method it offers is SHA-1. I had to eventually sign with `osslsigncode` to get this right. I was trying to cross-compile a Windows app on Linux, which is why the Mono solution appeared to make sense.
- setquk 8y agoOur EV cert shows an alert. Very fucking annoyed if I’m honest. And yes it was SHA-256. Several days and a pile of cash fucking around with WIX and signtool for what exactly?
- mnkypete 8y agoCheck this Stack overflow thread. For us it was cached SHA1 certificates in the cert chain: https://security.stackexchange.com/questions/109629/deprecation-of-sha1-code-signing-certificates-on-windows/113114#113114 https://security.stackexchange.com/questions/109629/deprecat... But yeah, it's a pain..
- setquk 8y agoThanks for the link. I don't think it was that but I'm going to check it thoroughly anyway.
- jenscow 8y agoThanks! I was considering an EV, but will now opt for the poor option. It's essentially a protection racket with price segmentation.
- setquk 8y agoIt does feel like that. We don't actually issue a signed copy now and we have had precisely one complaint and that was from an enterprise customer. We suggested they downloaded it themselves and gave them the sha256sum of the MSI and they were happy with that.