5 ms·
signtool badly needs to be updated. The interface is very confusing and the documentation, while fairly complete, isn't very helpful. That said, I just upgrade
by eco 8y ago
signtool badly needs to be updated. The interface is very confusing and the documentation, while fairly complete, isn't very helpful.
That said, I just upgraded ours and didn't have much trouble switching to sha256. There is one quirk about the order of the arguments due to some limitation with the timestamping servers. The documentation loudly points this out though. If it helps, here's my exact command line:
signtool.exe
sign /v
/n "Company, LLC"
/ph /d "Description"
/du "https://www.website.com"
/tr "http://timestamp.comodoca.com"
/td sha256 # /td must come after /tr
/fd sha256
executable.exe
Not being able to automate these EV hardware tokens because of the password is a pain that I'm already annoyed by though.
- 456hdsaq234g 8y agoCan you confirm that the reason the password is forced is the PKCS12 (pfx) import has flagged the key as requiring a password every signature? (and it cannot be disabled). I believe you can use mimikatz to forcibly strip the strong protection flag from the key. Microsoft says this is normally not possible, yet here we are. You might want to try downgrading the strong protection flag on the key material, it may allow for automated signing.
- gargravarr 8y ago> # /td must come after /tr Confirmed HTML
- jwilk 8y agoBut... it's </td></tr> in HTML. :-P
- spydum 8y agoPretty sure the new way is via PowerShell: Set-AuthenticodeSignature -HashAlgorithm "sha256" -IncludeChain "all" -FilePath "File" -Certificate $Cert -TimestampServer $TSUrl