4 ms·
I recently went through this same issue at my company - only found out about the change in requirements when I couldn't renew my cert at the previous provider.
by matharmin 3y ago
I recently went through this same issue at my company - only found out about the change in requirements when I couldn't renew my cert at the previous provider.
There is surprisingly little info available on how to do code signing for Windows now. I don't want to use a physical device - with fully remote teams it's not feasible. Eventually settled on Azure KeyVault with Digicert (I don't like Comodo aka Sectigo). There is really little info available on how to get it all to work together, and you have to spent around $600 before you can even try and see whether it can work.
Now that it's all configured, the setup works well. The new setup of doing the signing via Azure is more secure than storing the private keys on the CI system. But I never thought that signing an app for Windows would be more difficult than signing for macOS or iOS.
- alkonaut 3y agoI’m thinking that it might be by design that it’s somewhat hard and expensive.
- kuzko_topia 3y agoHey, is there any chance you could do a writeup on how you did things? due to the lack of information you mention, I think it might be useful for a lot of people there, including me.
- mike_hearn 3y agoIt's not the way the OP did it, but there's a blog post here on how to ship apps using cloud signing with the Conveyor tool. The title talks about Electron but it should work for any kind of app (not tested with .net) https://hydraulic.dev/blog/21-shipping-electron-apps-from-ci-using-hsm-certificates.html https://hydraulic.dev/blog/21-shipping-electron-apps-from-ci...
- matharmin 3y agoI'm probably not gonna get to a full post anytime soon, but I'll summarize here. This is from memory, so I may have some things wrong. 1. DigiCert CS certificate. You can validate your organization before paying anything, but it felt like we ended up in a low-priority queue because of that. After not hearing back for 2-3 weeks, I emailed support, then got validated in a day or two. 2. Azure KeyVault: "Premium" pricing model, since you need RSA 3072-bit or RSA 4096-bit HSM-backed keys. Generate a CSR here. There are a couple of annoying steps such as getting the access control setup right, but nothing too complicated. 3. Once you have a validated org and paid for the CS certificate, you can upload the CSR to DigiCert, and download the certificate. 4. "Merge" the certificate on Azure KeyVault. 5. Create an "application" on Azure which gives you API credentials. You need to copy a whole bunch of IDs: # key vault: azure-key-vault-url azure-key-vault-certificate # client application: azure-key-vault-tenant-id azure-key-vault-client-id azure-key-vault-client-secret You use the above with AzureSignTool to do the signing, e.g. from you CI system.
- jacquesm 3y ago> Eventually settled on Azure KeyVault with Digicert Somewhere at Microsoft two sales guys are high-fiving each other upon reading this comment. Mission. Fucking. Accomplished.