【问题标题】:Sign using cross sign使用十字符号签名
【发布时间】:2019-03-30 03:37:50
【问题描述】:

为什么签名有效但签名验证无效?

signtool sign /v /ac comodorsacertificationauthority_kmod.crt /tr http://timestamp.comodoca.com/rfc3161mydriver.sys

The following certificate was selected:
    Issued to: Company, Inc
    Issued by: COMODO RSA Extended Validation Code Signing CA
    Expires:   >..
    SHA1 hash: ....

Cross certificate chain (using machine store):
    Issued to: Microsoft Code Verification Root
    Issued by: Microsoft Code Verification Root
    Expires:   Sat Nov 01 16:54:03 2025
    SHA1 hash: 8FBE4D070EF8AB1BCCAF2A9D5CCAE7282A2C66B3

        Issued to: COMODO RSA Certification Authority
        Issued by: Microsoft Code Verification Root
        Expires:   Mon Apr 12 01:16:20 2021
        SHA1 hash: 106870659C069F248C8C0A05ACD871CABEB3CC38

            Issued to: COMODO RSA Extended Validation Code Signing CA
            Issued by: COMODO RSA Certification Authority
            Expires:   Mon Dec 03 02:59:59 2029
            SHA1 hash: 351A78EBC1B4BB6DC366728D334231ABA9AE3EA7

                Issued to: Company, Inc
                Issued by: COMODO RSA Extended Validation Code Signing CA
                Expires:   ...
                SHA1 hash: ...

Done Adding Additional Store Successfully signed: mydriver.sys

signtool verify /v /kp mydriver.sys

签名索引:0(主签名) 文件哈希(sha1):1EDBB6F9354413D1B0F1696BF713281954F75130

Signing Certificate Chain:
    Issued to: COMODO RSA Certification Authority
    Issued by: COMODO RSA Certification Authority
    Expires:   Tue Jan 19 02:59:59 2038
    SHA1 hash: AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4

        Issued to: COMODO RSA Extended Validation Code Signing CA
        Issued by: COMODO RSA Certification Authority
        Expires:   Mon Dec 03 02:59:59 2029
        SHA1 hash: 351A78EBC1B4BB6DC366728D334231ABA9AE3EA7

            Issued to: MyCompany, Inc
            Issued by: COMODO RSA Extended Validation Code Signing CA
            Expires:   ...
            SHA1 hash: ...

The signature is timestamped: Thu Oct 25 16:17:01 2018
Timestamp Verified by:
    Issued to: UTN-USERFirst-Object
    Issued by: UTN-USERFirst-Object
    Expires:   Tue Jul 09 21:40:36 2019
    SHA1 hash: E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46

        Issued to: COMODO SHA-1 Time Stamping Signer
        Issued by: UTN-USERFirst-Object
        Expires:   Tue Jul 09 21:40:36 2019
        SHA1 hash: 03A5B14663EB12023091B84A6D6A68BC871DE66B

SignTool Error: A certificate chain processed, but terminated in a root
    certificate which is not trusted by the trust provider.

Number of files successfully Verified: 0
Number of warnings: 0
Number of errors: 1

【问题讨论】:

  • 你在机器的 Windows 密钥库中有根证书吗?
  • 我有一切可以正确签名。 Comodo 支持指出我应该使用 /pa 开关而不是 /pk ,但这不是他们在网页上写的。

标签: windows kernel driver code-signing-certificate


【解决方案1】:

也许你应该使用 verify /ds 1 /v?? /ds 1 在哪里是索引 1,而不是 0? https://docs.microsoft.com/en-US/dotnet/framework/tools/signtool-exe

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2017-11-29
    • 2013-04-15
    • 2023-04-11
    • 2018-11-27
    • 2021-06-09
    • 2016-03-08
    • 2013-08-08
    • 2017-03-23
    相关资源
    最近更新 更多