3 ms·
I’ve found the easiest option available here is through using Azure KeyVault to store the keys. I use a custom module to sign my PowerShell scripts and dlls [1]
by jborean93 3y ago
I’ve found the easiest option available here is through using Azure KeyVault to store the keys. I use a custom module to sign my PowerShell scripts and dlls [1] for this because I can integrate it with OIDC to sign the code using the keys stored in the Azure HSM. While the builtin pwsh Set-Authenticode cmdlet can’t do this currently there are other options that rely on Window’s authenticode APIs like AzureSignTool [2] that I highly recommend.
While I’m unsure if Azure is suitable for actual companies I think the risk is ok for what I need it for and the API quality as well as OIDC support make it quite nice to use with GHA.
[1] https://github.com/jborean93/PowerShell-OpenAuthenticode https://github.com/jborean93/PowerShell-OpenAuthenticode
[2] https://github.com/vcsjones/AzureSignTool https://github.com/vcsjones/AzureSignTool
- electroly 3y agoI was looking into Azure Key Vault Managed HSM and it appears to be vastly more expensive than the $629/year from Digicert. A Managed HSM Pool is $3.20/hour. Am I missing something?
- veeti 3y agoYou don't need a HSM, just a HSM backed key. It costs like $5 a month.
- electroly 3y agoCan you point me at some more information about the difference? This would seem to be a much better deal than paying Digicert, but I'm confused about how it can be so cheap? Isn't the required for an HSM at all the reason it's so much more expensive now at other CAs?
- veeti 3y agoI don't know what happens under the hood, but presumably a HSM key is on a shared HSM with other people whereas what you're talking about will get you a dedicated HSM. We have set up Key Vault for code signing using this and it does work.
- electroly 3y agoThanks so much for this. I will dig into this option, and it seems the ImageMagick people have been clued into the same solution.
- gloosx 3y agoThis whole thing is set-up to earn your money under the cover of protecting somebody from something, so all the prices you see are random manager thoughts on how much they want to get. There is no reasoning behind this price really and it is just arbitrary price made from rules "as high as possible" and "low enough they still buy from us". Microsoft certificate prices are essentially like drug prices, and the "authorized resellers" is basically a drug cartel