8 ms·
Just throwing in that the dollar value isn't the only cost. I've been using an automated release workflow tomanage signing, eg https://github.com/technion/rust
by technion 3y ago
Just throwing in that the dollar value isn't the only cost. I've been using an automated release workflow tomanage signing, eg
https://github.com/technion/rustypwneddownloader/blob/main/.github/workflows/release.yml https://github.com/technion/rustypwneddownloader/blob/main/....
This worfklow isn't usable with these new rules, and I'm having a hard time with the assertion that moving builds to my desktop to use a hardware signing key and uploading them in a non automated, non transparent fashion is an improvement on security.
- electroly 3y agoI'm in exactly the same boat; doing the same thing to store my OV .pfx certificate in a GitHub Actions secret. My certificate expires in November 2024 and I'm undecided what I'll do. It was hard enough to get a certificate as a solo developer and not a corporation. Still, though, it should just be a matter of money. The $629/year cloud-hosted HSM mentioned in the OP will do it. If you pay that, you can use this procedure to make it work with GitHub Actions with the same sort of signtool or Set-AuthenticodeSignature command that you use now: https://docs.digicert.com/en/software-trust-manager/ci-cd-integrations/plugins/github-custom-action-for-keypair-signing.html https://docs.digicert.com/en/software-trust-manager/ci-cd-in...
- jborean93 3y agoI’ve found the easiest option available here is through using Azure KeyVault to store the keys. I use a custom module to sign my PowerShell scripts and dlls [1] for this because I can integrate it with OIDC to sign the code using the keys stored in the Azure HSM. While the builtin pwsh Set-Authenticode cmdlet can’t do this currently there are other options that rely on Window’s authenticode APIs like AzureSignTool [2] that I highly recommend. While I’m unsure if Azure is suitable for actual companies I think the risk is ok for what I need it for and the API quality as well as OIDC support make it quite nice to use with GHA. [1] https://github.com/jborean93/PowerShell-OpenAuthenticode https://github.com/jborean93/PowerShell-OpenAuthenticode [2] https://github.com/vcsjones/AzureSignTool https://github.com/vcsjones/AzureSignTool
- electroly 3y agoI was looking into Azure Key Vault Managed HSM and it appears to be vastly more expensive than the $629/year from Digicert. A Managed HSM Pool is $3.20/hour. Am I missing something?
- veeti 3y agoYou don't need a HSM, just a HSM backed key. It costs like $5 a month.
- electroly 3y agoCan you point me at some more information about the difference? This would seem to be a much better deal than paying Digicert, but I'm confused about how it can be so cheap? Isn't the required for an HSM at all the reason it's so much more expensive now at other CAs?
- veeti 3y agoI don't know what happens under the hood, but presumably a HSM key is on a shared HSM with other people whereas what you're talking about will get you a dedicated HSM. We have set up Key Vault for code signing using this and it does work.
- electroly 3y agoThanks so much for this. I will dig into this option, and it seems the ImageMagick people have been clued into the same solution.
- gloosx 3y agoThis whole thing is set-up to earn your money under the cover of protecting somebody from something, so all the prices you see are random manager thoughts on how much they want to get. There is no reasoning behind this price really and it is just arbitrary price made from rules "as high as possible" and "low enough they still buy from us". Microsoft certificate prices are essentially like drug prices, and the "authorized resellers" is basically a drug cartel
- hermitcrab 3y ago$629 per year for doing some basic ID checks and basically multiplying 2 prime numbers together. What a scam.
- universa1 3y agoHmm, not sure on GitHub actions, but wouldn't a local ci runner solve this? A small sff/Atom PC for approx 100$ with the hardware key attached... So all that would change is where the signing part happens, either in the cloud or on your local runner... Not sure which way to lean if this is an improvement or not security wise :-)
- entuno 3y agoAnd if it discourages people from signing their binaries at all, then that's definitely a negative outcome.
- mike_hearn 3y ago> moving builds to my desktop to use a hardware signing key and uploading them in a non automated, non transparent fashion is an improvement on security For most projects it is an improvement, for better or worse. First issue: private keys stored in files can be stolen silently, and then the only recourse is revocation. That's the main reason for the HSM requirement: malware authors have been doing this for some time now and revocation is difficult/expensive for various reasons. An HSM can also be stolen but only in the old fashioned way of breaking into your office or home and grabbing it, which you're going to notice. You may object that the credentials for using the HSM can be stolen, and that's true, but they can also be changed easily and quickly. So if you notice that your PIN has been keylogged, you can recover from the compromise then change the PIN and you're done, no need to revoke the certificate. Second issue: automated signing in CI can actually be risky. It means anyone who can push code to your CI system can get code signed as yourself, possibly without you even being aware of it. The key is held online at all times, so obviously if the CI system gets hacked then it's game over, but even without that it boils down to anyone who can push code into the system becoming a weak point, especially because CI systems are running lots of arbitrary code without being closely monitored. CI signing is at best 1-factor security. If you sign locally then the key can be (literally) offline until the moment you do a release, and access to it can be constrained via 2-factor auth: the key is something you have, the credential is something you know. So this is quite secure. For signing nightly dev builds, internal tools and other transient binaries that shouldn't get out into the wild anyway, you can self-sign which is free.
- electroly 3y ago"Cloud HSMs" are allowed by the CA/B rules which wholly negate the benefit for that second issue and bring us back into the situation where anyone who checks code into CI can sign with the key. The CA/B rules are really just concerned with the first issue, right?
- mike_hearn 3y agoYes, the current rules aren't attempting to litigate full supply chain security. If you look at how the cloud signing services work though, the underlying protocols are designed to allow 2FA authenticators. They give you a TOTP seed, it's not just a basic password. They can't prove the seed was put into a real 2FA authenticator app though, so in practice you can use it as if it's a password.