PDA

View Full Version : Code Signing Cert by Comodo



NewsArchive
08-12-2014, 01:23 PM
Quick question about these certificates.

Everything I can find tells me that their _maximum_ period is for three years.

But I downloaded a suspect installer file to check its certificate.
The certificate says it is valid for 5 years. It is issued to an address in Saratov,
Russia. see attached.

Are these certificates being forged in Russia?

Issuing Comodo office shows:
CN = COMODO Code Signing CA 2
O = COMODO CA Limited
L = Salford
S = Greater Manchester
C = GB


JohnG

NewsArchive
08-12-2014, 01:24 PM
John,

> Quick question about these certificates.
>
> Everything I can find tells me that their _maximum_ period is for three
> years.

As far as I know, the "new" certificates (with kernel driver signing
capability) are valid for between one to three years depending on your
purchase choice. The certificate you mentioned is an "old" certificate
type.

http://www.lindersoft.com/forums/showthread.php?t=43220
http://www.instantssl.com/code-signing/code-signing-faq.html

Friedrich

NewsArchive
08-12-2014, 01:25 PM
Friedrich

>The certificate you mentioned is an "old" certificate type.

Thanks. That would explain it.

John