I’m distributing unsigned binaries not because I care about the $200 for a cert, but I don’t want to spend hours figuring out a signing flow.
I’m distributing unsigned binaries not because I care about the $200 for a cert, but I don’t want to spend hours figuring out a signing flow.
Seems not to make the process easier, because apparently your organization has to be more than 3 years old[2] to be eligible.
For the traditional way with a third-party cert provider someone on Reddit made a comparison table[3]. The whole thread is interesting.
[1] https://learn.microsoft.com/en-us/azure/trusted-signing/over...
[2] https://learn.microsoft.com/en-us/answers/questions/2082252/...
[3] https://www.reddit.com/r/electronjs/comments/17sizjf/a_guide...
> We are working on making the functionality available for organizations that were incorporated less than 3 years ago. We don't have an ETA yet to share.
From your link at [2]
Here is the GitHub action for file signing using Trusted Signing: https://github.com/Azure/trusted-signing-action.
[1] https://techcommunity.microsoft.com/blog/microsoft-security-...
My formula was: Github actions, Sectigo usb key, physical windows machine in the office that runs a self-hosted action runner that does the signing step.
1. Get an EV certificate from a trusted CA [1]. That will run $400-800.
2. Use managed Trusted Signing from Azure. [2] Identity validation takes ~a week. Signing can be done via web or CLI. This does require a tax history of 3+ years. [3]
[1] https://learn.microsoft.com/en-us/windows-hardware/drivers/d...
[2] https://learn.microsoft.com/en-us/azure/trusted-signing/quic...
[3] https://learn.microsoft.com/en-us/azure/trusted-signing/quic...
You can execute it on any platform that supports Java, so I have Linux builds cross compiling to windows with clang and then sign with jsign: https://github.com/BrowserWorks/Waterfox/blob/7eda3b998a56ad...
[1] https://trustzone.com/knowledge-base/purchasing-an-ev-code-s... [2] https://trustzone.com/knowledge-base/purchasing-an-ev-code-s...
https://support.sectigo.com/IS_KnowledgeDetailPage?Id=kA03l0... is an example explaining how to get both a CSR and an attestation certificate from a YubiKey 5 FIPS, on Windows.
https://support.yubico.com/hc/en-us/articles/360016614840-Co... explains how to use Windows' signtool with a Yubikey.
Using a YubiKey does require that you provide your PIN every time you want to do a signature, which limits how much you can automate things. A YubiHSM would remove that requirement, and might be able to work with a self-hosted GitHub Actions Runner, but it's more expensive, and you'd want confirmation from your CA (Sectigo, for example) that a YubiHSM is OK.
AutoHotkey is your friend!
When I set up our code signing machine at AltspaceVR ten years ago, I wrote a simple little AutoHotkey script that watched for the signtool PIN popup and typed in the PIN. It was maybe 15-20 lines of code.
Problem solved.
Some other signing that works in the cloud and has support for GitHub Actions would be DigiCert's KeyLocker (note: every signed binary is counted and by default the subscription only contains 1000 signings): https://www.digicert.com/signing/code-signing-certificates#c...
This blog post below is great. It works through the process, including the truly weird/awful UX choices Azure makes. I archived it on wayback in case it ever disappears.
https://www.hendrik-erz.de/post/code-signing-with-azure-trus...
you can see a usage example here: https://github.com/mscrivo/OotD/blob/main/.github/workflows/...
There's a lot to it, and expect a ton of a back and forth emails with a CA to get an EV Cert.
Here's some example code for generating the CSR (Certificate signing request) to submit to a CA.
That part is trivial, the real pain comes from dealing with the certificate providers.
...and you need to have a corporation?
I thought corporations were pseudo-humans. Turns out it may be the other way around.
Import HSM-protected keys to Key Vault (BYOK) https://learn.microsoft.com/en-us/azure/key-vault/keys/hsm-p...
I guess that allows you to get your own cert (example: from DigiKey) for your own HSM (example: YubiKey) and then upload it.
That's what we researched before we abandonded the approach and kept code-signing by manually downloading the build, signing on a specific machine where only one architect had access. What could ever go wrong?
How would that ever get worked into GitHub Actions?
Although I think even OV require HSM now for local, with some options for hosted services like Azure Trusted Signing.
But I really don't know. I read details only to end up not certain.
Smartscreen, AV warnings, etc use a reputation-based system. No amount of money makes you truly immune from warnings, but paying for EV does give you a higher default reputation. Since there is no longer any file-vs-HSM distinction between EV and OV, it is simply a cost for more default reputation. Any business will pay it easily.
(My prediction is that OV/EV will consolidate to a single offering, in the same way that EV for web SSL has been phased-out.)
Azure Trusted Signing is an all-in-one service that creates keys, purchases the certificate, and hosts the HSM for you. It's still OK to do all these things separately e.g. purchase the cert from Globalsign and use Azure Key Vault as the HSM (you have to pay for the 5 USD/mo service for the larger key size, instead of the cheap one).
ATS is still somewhat new and has not fed into toolchains like https://github.com/sassoftware/relic yet. Although https://github.com/ebourg/jsign does support it.
1. https://knowledge.digicert.com/alerts/code-signing-changes-i...
https://www.mgtek.com/smartcard
For automating pin entry