PDA

View Full Version : Code Signing Renewal



NewsArchive
03-07-2023, 01:45 PM
Hi All

This NG looks pretty dead right now but here is hoping.

I need to do a code signing renewal again. I seem to recall some notes
from Jane that gave a step by step. Is this still available? Is there
an update?

Cheers
Andre

NewsArchive
03-07-2023, 01:45 PM
Hi Andre,

https://www.beachbunnysoftware.com/SB/Comodo2020.pdf

Don't know of any update sorry.

Graham

NewsArchive
03-07-2023, 01:46 PM
Thanks Graham - nice to hear from you.

Andre Labuschagne

NewsArchive
03-07-2023, 01:46 PM
I just renewed my certificate today.

Did it using Windows 11 and Edge and was going to update the PDF I
last did 3 years ago. Some of my adventures are documented in the
link Jeff posted.

But... as Jeff points out, everything appears to be changing on June
1. (Hardware tokens and/or cloud-based signing). So not sure whether
there's any point to updating the PDF.

OTOH, I'm glad I've got a new cert that's good for 3 years. By that
time, maybe the new madness will be sorted out. Or I'll have gotten a
job doing needlepoint....

jf

NewsArchive
03-07-2023, 01:47 PM
> OTOH, I'm glad I've got a new cert that's good for 3 years. By that
> time, maybe the new madness will be sorted out. Or I'll have gotten a
> job doing needlepoint....

:-)

It is a mess.

I ended up using IE and going straight to sectigo store.

We updated our DUNS info in 2016 but it never made it into Dun and
Bradstreet - so we have that going for us.

SSL and Code Signing is a joke. We just have to smile and bear it.

Andre Labuschagne

NewsArchive
03-07-2023, 01:49 PM
Andre,

> We just have to smile and bear it.

Please close the door first.... PLEASE!<g>

My Eyes, MY EYES!

NewsArchive
03-07-2023, 01:50 PM
On 24/01/2023 17:44, My Eyes, MY EYES! wrote:
> Please close the door first.... PLEASE!<g>

:-)

The saga - song and dance - continues.

Dealing directly with Manchester now. Lovely lass but could very well
be a city in Bangladesh. The world needs a new common language, so when
the aliens arrive they have only one set of mumblings to deal with.

Just kidding - the support has been great so far.

Turns out Dun and Bradstreet had something correct that I got wrong -
instead of the registered physical address on corporate documents I gave
them cloud 9 hovering above camel thorn tree 666 somewhere in darkest
Africa. I mixed up where we actually are [de facto] with where we
legally are [de jure]. Schroedinger's cat comes to mind. Maybe we are
decidedly not, or anywhere, or nowhere, or in a parallel universe.

Tomorrow we continue the interrogation. I lost the battle to get the
required proof of human existence to be executed with a photo shoot [or
should that be photoshop] with bikini on the beach. Instead a dull
office impression had to suffice.

A stiff gin and tonic and I am ready to help with the next set of questions.

Cheers
Andre

NewsArchive
03-07-2023, 01:51 PM
Hi Andre,

>
> Dealing directly with Manchester now. Lovely lass but could very well
> be a city in Bangladesh. The world needs a new common language, so
> when the aliens arrive they have only one set of mumblings to deal with.
>

I'm not at all sure that the human race will be the one they will want
to talk to!<g>

Best regards,

--
Arnor Baldvinsson
Icetips Alta LLC

NewsArchive
03-07-2023, 01:51 PM
> I'm not at all sure that the human race will be the one they will want
> to talk to!<g>

Indeed - I know many animals that would be a better bet.

Andre Labuschagne

NewsArchive
03-07-2023, 01:52 PM
>> I'm not at all sure that the human race will be the one they will want
>> to talk to!<g>
>
> Indeed - I know many animals that would be a better bet.

Mark Twain said it best:

https://www.goodreads.com/quotes/668287-the-more-i-learn-about-people-the-more-i-like

:-)

Charles

--
-------------------------------------------------------------------------------------------------------
Charles Edmonds

cjeByteMeSpammers@lansrad.com (remove the "ByteMeSpammers" to email me)

www.clarionproseries.com - ProDocument, ImageEx, ProScan, ProImage, ProPath
and other Clarion developer tools!
www.lansrad.com - "Intelligent Solutions for Universal Problems"
-------------------------------------------------------------------------------------------------------

NewsArchive
03-07-2023, 01:53 PM
> The saga - song and dance - continues.

The saga has now ended - many bottles of whiskey later and multiple
visits to the therapist.

The long and short of it is the certificate eventually arrived after
chasing Manchester every day. The main problems were lost in
translation stuff and poor communication from them.

We now have a dedicated file for this exercise with meticulous notes on
how to expedite and decided on only one year certificates as practice
makes perfect. We now how to handle this puppy. Three years is way too
far in the distance. The planet has changed dramatically by then.

Depending on how we feel next year or if the aliens have not arrived yet
we may decide on three years.

Cheers
Andre

NewsArchive
03-07-2023, 01:53 PM
Good luck with that, Andre. :(

It sounds as if we will not be able to buy this kind of certificate
after June. It will be certs on a dongle. Buy extra dongles. Keep
one in your safe deposit box.
I'm glad my new old-fashioned cert is good for 3 years, anyway.

Didn't you read those links from Clarion Hub?

That's why I decided not to bother updating my how-to PDF... it it's
going to be out-of-date in a few months.

https://www.youtube.com/watch?v=221vgznA7WA
https://www.ssl.com/article/code-signing-key-storage-requirements-will-change-on-june-1-2023/
https://www.ssl2buy.com/wiki/changes-issuing-ov-code-signing-certificate

jf

NewsArchive
03-07-2023, 02:03 PM
Hi Andre,

> We now have a dedicated file for this exercise with meticulous notes
> on how to expedite and decided on only one year certificates as
> practice makes perfect. We now how to handle this puppy. Three years
> is way too far in the distance. The planet has changed dramatically
> by then.
>
> Depending on how we feel next year or if the aliens have not arrived
> yet we may decide on three years.

I can 100% guarantee that your file is already outdated! I met a guy
from Comodo once at a conference and it was positively frightening to
hear about how that was operated! The incompetence, ignorance and
carelessness was just astounding. And he admitted as much. And this is
what we are "protecting" our products with!

Best regards,


> rnor Baldvinsson

Icetips Alta LLC

NewsArchive
03-07-2023, 02:04 PM
> It sounds as if we will not be able to buy this kind of certificate
> after June. It will be certs on a dongle. Buy extra dongles. Keep
> one in your safe deposit box.
> I'm glad my new old-fashioned cert is good for 3 years, anyway.
>
> Didn't you read those links from Clarion Hub?
>
> That's why I decided not to bother updating my how-to PDF... it it's
> going to be out-of-date in a few months.
>
> https://www.youtube.com/watch?v=221vgznA7WA
> https://www.ssl.com/article/code-signing-key-storage-requirements-will-change-on-june-1-2023/
> https://www.ssl2buy.com/wiki/changes-issuing-ov-code-signing-certificate
>
> jf

Hi Jane

I did not read/listen to any of that.

The entire code signing / ssl industry looks more and more like a
racket. It does explain the evolution of LE.

Maybe there will be a similar move for CS.

Human beings have this propensity to try and make things complicated and
obtuse - it is a Seinfeld moment - with males always trying to assign
the most important sounding titles to their job positions.

Thanks for the links - everything may change before June anyway. And
existing certificates may just stop working. None of this security
actually means anything. Developers who work in the field of encryption
will tell you so. Some of them have little games who can crack what
first. - over a pint or two. One of my mentors did this for fun at
weekly computer club meetings.

Anyways - till next time if it ever comes around.

Cheers
Andre

NewsArchive
03-07-2023, 02:04 PM
> I can 100% guarantee that your file is already outdated! I met a guy
> from Comodo once at a conference and it was positively frightening to
> hear about how that was operated! The incompetence, ignorance and
> carelessness was just astounding. And he admitted as much. And this is
> what we are "protecting" our products with!

Hi Arnor

I would say you are correct - clearly it is out of date.

Fortunately for me my approach to life is one of a stoic. I do not
expect anything to work. Especially anything technological. I guess I
am a techno pessimist - accurately defined as a techno optimist with
loads of experience.

When you break it down there is no real protection in the world of
technology.

Cheers
Andre