I was incredibly salty about this. I didn't name the CA, because they're actually nice to have reduced price for Open Source projects, but Microsoft really needs to drag the whole process into the 21st century.
The process and infrastructure reminds me very much of TLS before Let's Encrypt. If this is something that every developer needs to do for every exe, it can't be like getting an EV certificate for a Netscape Server. I thought Apple's often-buggy signing was bad, but at least they've tried to make it a one checkbox paid for in a straightforward transaction.
I would have signed with SHA-2, which for inexplicable reason is not the default despite deprecation, but my signtool crashed when I enabled it.