Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The signature in MSI package does not contain a timestamp #2752

Open
2 tasks
rafabailon opened this issue Jan 8, 2024 · 0 comments
Open
2 tasks

The signature in MSI package does not contain a timestamp #2752

rafabailon opened this issue Jan 8, 2024 · 0 comments
Labels
level/task Subtask issue module/install qa_known Issues that are already known by the QA team type/bug Bug issue

Comments

@rafabailon
Copy link
Member

rafabailon commented Jan 8, 2024

Description

In certificates check it has been found that the signature in MSI package does not contain a timestamp.

Found in Scheduled certificates review - 2024 Monthly #01

image

Details

When it comes to digital signatures, timestamping refers to the process of including an electronic timestamp in your signature to possibly extend the validity of the signing certificate.

Therefore, if a certificate includes a timestamp, it will validate the certificate by verifying the signature against the time it was signed, and not the time you are running the software. And if not and a certificate has expired, then not having a digital signature timestamp will essentially block the application from being used.

Steps to Reproduce

To reproduce the error you must follow the following steps:

image

image

Tasks

  • Add timestamp to the MSI Package Signature
  • Check that the MSI Package Signature has timestamp
@rafabailon rafabailon added level/task Subtask issue type/bug Bug issue qa_known Issues that are already known by the QA team labels Jan 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
level/task Subtask issue module/install qa_known Issues that are already known by the QA team type/bug Bug issue
Projects
None yet
Development

No branches or pull requests

2 participants