public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* Should cygwin's setup*.exe be signed using Sign Tool?
@ 2015-04-02 18:13 David A. Wheeler
  2015-04-02 22:35 ` Andrey Repin
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: David A. Wheeler @ 2015-04-02 18:13 UTC (permalink / raw)
  To: cygwin

Running setup*.exe produces "Publisher: Unknown publisher", and it's doubtful that many people check the signature of the .exe file before running.  Even if they did, there's the problem that the signature comes from the same place.

Has Cygwin considered signing the installer using Sign Tool? More info:
  https://msdn.microsoft.com/en-us/library/windows/desktop/aa387764%28v=vs.85%29.aspx
  http://blog.didierstevens.com/2008/12/31/howto-add-a-digital-signature-to-executables/

I believe signing it this way would eliminate the "unknown publisher"; it would also protect the many people who don't follow the current signature-checking process.  This would create a strong barrier against code subversion after release.

The signed executable could also be signed using the current process, so you don't need to *eliminate* any capability.  I can't provide a patch to do this, obviously :-).

--- David A. Wheeler


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2015-04-09 13:44 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-04-02 18:13 Should cygwin's setup*.exe be signed using Sign Tool? David A. Wheeler
2015-04-02 22:35 ` Andrey Repin
2015-04-03  3:17   ` David A. Wheeler
2015-04-03  1:23 ` Bryan Berns
2015-04-03  3:27   ` David A. Wheeler
2015-04-03 11:37     ` Corinna Vinschen
2015-04-09 13:05 ` Jon TURNEY
2015-04-09 13:44   ` René Berber

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).