PDA

View Full Version : I hate CodeSigning



NewsArchive
01-26-2016, 01:44 AM
Have to live with it but a real pain. Following all the threads, but
still not there yet. Not sure of the cause, using a Win 7 machine,
wrong setting somewhere, the newer 8.1 codesign.exe I downloaded.

Don Harvey

NewsArchive
01-26-2016, 01:45 AM
Don,

> Have to live with it but a real pain. Following all the threads,
> but still not there yet. Not sure of the cause, using a Win 7
> machine, wrong setting somewhere, the newer 8.1 codesign.exe I
> downloaded.

See the million posts below <g>.

For example:
http://www.lindersoft.com/forums/showthread.php?47051-Again-SHA-1

Most Windows 7 machines do NOT support dual code-signing. You need Windows
8.1 or better to have a rock solid code-signing environment.

So you did NOT follow all the threads <g> ;-) It's not a code-signing
issue. It's a Windows 7 issue!

Friedrich

NewsArchive
01-26-2016, 09:35 AM
Lee mentioned an SDK that satisfies the code signing ability's
requirements on Windows 7.

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-26-2016, 11:50 AM
I know, have printed out or read 76 items, it must be on item 77 :)

Guess probably the easiest approach is to update this machine.

Don Harvey

NewsArchive
01-27-2016, 02:25 AM
Printing out doesn't count unless you actually read them <G>

Jane Fleming

NewsArchive
01-27-2016, 02:26 AM
Hi Friedrich,

> Most Windows 7 machines do NOT support dual code-signing. You need Windows
> 8.1 or better to have a rock solid code-signing environment.

My 32bit Development Win7 VM hasn't been updated since early 2015 and it
can still happily dual code sign;) I will upgrade it to W10 soon, but
until then it's saying in early 2015 mode<g>

Best regards,

--
Arnor Baldvinsson
Icetips Alta LLC

NewsArchive
01-27-2016, 02:27 AM
Of course I did, it was exciting reading :)

Upgrading to Win10 solved the problem here. Was reluctant for fear some
of the older programs would no longer work but thankfully the upgrade
was pretty smooth.

Don Harvey

NewsArchive
01-27-2016, 06:22 AM
Hi Jeff,

> Lee mentioned an SDK that satisfies the code signing ability's
> requirements on Windows 7.

IMO, it depends on the specific patch level of the Windows 7 machine.
Unfortunately, Microsoft changed something code-signing wise in one of the
2015 patches.

See attached screenshots. This is a Windows 7 SP1 machine and dual
SHA-1/SHA-2 code-signing always fails. Tested with signtool.exe versions
6.1.7000, 6.1.7600, 6.2.9200, 6.3.9600 and 10.0.20140. SHA-1 in the dual
code-signing process always succeeds, but SHA-2 fails. But it's not caused
by the SHA-2 signature per-se. SHA-2 only signing even works with 6.1.7000
(according to Microsoft, it was version 6.1.7600 that introduced SHA-2).

Friedrich

NewsArchive
01-27-2016, 06:30 AM
Hi Arnor,

>> Most Windows 7 machines do NOT support dual code-signing. You need
>> Windows 8.1 or better to have a rock solid code-signing environment.
>
> My 32bit Development Win7 VM hasn't been updated since early 2015 and it
> can still happily dual code sign;) I will upgrade it to W10 soon, but
> until then it's saying in early 2015 mode<g>

I also had a perfectly working dual code-signing environment under Windows 7
SP1 (64-bit). But on September 25, 2015 I updated the machine and one of
the security updates killed "dual" mode <g>.

Friedrich

NewsArchive
01-27-2016, 10:12 AM
Friedrich,

> This is a multi-part message in MIME format.
> -----------------2950704976
> Content-Type: text/plain; charset=us-ascii
>
> Hi Jeff,
>
> > Lee mentioned an SDK that satisfies the code signing ability's
> > requirements on Windows 7.
>
> IMO, it depends on the specific patch level of the Windows 7 machine.
> Unfortunately, Microsoft changed something code-signing wise in one of the
> 2015 patches.

Did you change something in your reader?

Many of your messages today are kinda messed up and look like the
above, at least in my reader.<g>

Lee White

NewsArchive
01-28-2016, 01:59 AM
Lee,

> Did you change something in your reader?
>
> Many of your messages today are kinda messed up and look like the
> above, at least in my reader.<g>

No, I did not change anything on this machine for years ;-)

Friedrich

NewsArchive
01-28-2016, 02:00 AM
Hi Friedrich,

> I also had a perfectly working dual code-signing environment under
> Windows 7 SP1 (64-bit). But on September 25, 2015 I updated the
> machine and one of the security updates killed "dual" mode <g>. Friedrich

I remember you saying that which is why this VM isn't going to get
updated until I have moved everything over to W10 as I'm not supporting
two dev VMs;)

Best regards,

--
Arnor Baldvinsson
Icetips Alta LLC

NewsArchive
01-28-2016, 10:11 AM
Friedrich,

> No, I did not change anything on this machine for years ;-)

Oops, it was me! Some how Ctrl+R got hit which puts Agent in the mode
to display raw messages.

I'll retreat to my cave now!<g>

--
Lee White

RPM Report Viewer.: http://www.cwaddons.com/products/rpm/
RPM Review........: http://www.clarionmag.com/cmag/v11/v11n06rpm.html
Report Faxing.....: http://www.cwaddons.com/products/afe/
---Enroll Today---: http://CWaddons.com

Creative Reporting: http://www.CreativeReporting.com

Product Release & Update Notices
http://twitter.com/DeveloperPLUS

Windows 8 brings us "The Oval, Bumper Car, Roller Coaster of Wait!"
And, now, Windows 10 brings us "The Inch Worm, Bumper Car of Wait!"

NewsArchive
01-28-2016, 10:11 AM
Been there and done that at least 3 times in 10 years.

Just long enough in between to forget how to fix it each time<g>

Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.

Grammar troll's, are the worse.

NewsArchive
01-28-2016, 10:12 AM
Lee,

>> No, I did not change anything on this machine for years ;-)
>
> Oops, it was me! Some how Ctrl+R got hit which puts Agent in the mode
> to display raw messages.
>
> I'll retreat to my cave now!<g>

<BG> ;-)

Friedrich