PDA

View Full Version : SetupBuilder 8.2 provides built-in support option for SHA-2



NewsArchive
11-24-2014, 09:41 AM
All,

The next SetupBuilder 8.2 update will provide a built-in support option for
the SHA-2 (SHA-256) Hashing Algorithm. See attached screenshots. One
executable signed with the default SHA-1, the other executable signed with
the "new" SHA-2.


DETAILED INFORMATION:

As you probably know, Microsoft has published a security advisory on
"Deprecation of SHA-1 Hashing Algorithm for Microsoft Root Certificate
Program". The new policy takes effect after January 1, 2016 and requires
CAs to migrate to the stronger SHA-2 hashing algorithm.

In summary, Windows will cease accepting SHA-1 certificates on January 1,
2017. To continue to work with Microsoft platforms, all SHA-1 SSL
certificates issued before or after this announcement must be replaced with
a SHA-256 (SHA-2) equivalent by January 1, 2017. Organizations need to
develop a migration plan for any SHA-1 end-entity SSL certificates that
expire after January 1, 2017 and SHA-1 code signing certificates that expire
after January 1, 2016. SHA1 code signing certificates that are time stamped
before 1 January 2016 will be accepted until such time when Microsoft
decides SHA1 is vulnerable to pre-image attack. Microsoft will give new
consideration to the SHA deprecation deadlines in July 2015.

1. Customers should "renew" with SHA-2 end-entity and intermediate
certificates.

2. Microsoft will cease trusting Code Signing Certificates using SHA-1 on
January 1, 2016.


WARNING:

If you use SHA-2 today, expect trouble. Most applications, servers and
browsers now support SHA-2, however some older operating systems such as
Windows XP prior to Service Pack 3, and some mobile devices do not. Vista
needs a specific patch (KB2763674) to handle SHA-2 executables. At the
moment it is best to keep using SHA-1 as long as you can!

For example:
http://support.microsoft.com/kb/2763674

Before the SHA-1 algorithm is formally deprecated by Microsoft, it is
important to ensure your organization and those relying on your
infrastructure are benefiting from SHA-2 support by installing the latest
version of the application or browser and applying all known security
updates to your operating system.


COMODO:

Comodo will support only SHA-2 on all 3 year code signing certificates.
They will also confirm policies at this time regarding 2 year SHA-1 code
signing certificates.

http://www.comodo.com/e-commerce/SHA-2-transition.php

Comodo told us that if the code-sign certificate order goes beyond
01-Jan-2016 their system will automatically issue of the SHA-2 chain!

As usual, SetupBuilder is ready for the future.

Friedrich

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official COMODO Code Signing and SSL Certificate Partner

NewsArchive
11-25-2014, 02:45 AM
Next week, MS is changing it to SHA-X

>
>As usual, SetupBuilder is ready for the future.

Jeff Slarve
www.jssoftware.com
www.twitter.com/jslarve
I'll search help files & Google for you.

NewsArchive
11-25-2014, 02:47 AM
Some people just put the nattering in nabob. <g>

[/ ObscureSpiroAgnewReference]

Jane Fleming

NewsArchive
11-25-2014, 02:49 AM
I'll be on the Jimmy Kimmel show tomorrow night<g>

Jeff Slarve
www.jssoftware.com
www.twitter.com/jslarve
I'll search help files & Google for you.

NewsArchive
11-25-2014, 02:50 AM
Jeff,

> Next week, MS is changing it to SHA-X

I figured they'd go for reality and use SHAm!

Lee White

NewsArchive
11-25-2014, 02:50 AM
Jeff Slarve
www.jssoftware.com
www.twitter.com/jslarve
I'll search help files & Google for you.

NewsArchive
11-25-2014, 05:12 AM
Okay, as far as I can see from all the emails sent to our support, this new
Windows Secure Hash Algorithm 256 (SHA-2) thing has made quite a few
developers EXTREMELY nervous.

Don't panic! More information, tips and tricks to follow soon ;-) We know
you're busy, so we have done all the homework and research to handle SHA-2
(including as much as possible backward compatibility).

So just sit back and relax <g>.

Friedrich

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official COMODO Code Signing and SSL Certificate Partner

NewsArchive
11-26-2014, 05:21 AM
> Don't panic! More information, tips and tricks to follow soon ;-) We know
> you're busy, so we have done all the homework and research to handle SHA-2
> (including as much as possible backward compatibility).
>
> So just sit back and relax <g>.

THAT, is one of the #1 reasons every developer should be using
SetupBuilder!


:-)

Charles


--
-------------------------------------------------------------------------------------------------------
Charles Edmonds

cjeByteMeSpammers@lansrad.com (remove the "ByteMeSpammers" to email me)
www.clarionproseries.com - ProScan, ProImage, ProPath and other Clarion
developer tools!
www.ezchangelog.com - "Free ChangeLog software to manage your projects!"
www.setupcast.com - "A revolutionary new publishing system for software
developers - enhanced for SetupBuilder users!"
www.pagesnip.com - "Print and Save the Web, just the way you want it!"
www.ezround.com - "Round Corner HTML tables with matching Banners, Buttons
and Forms - Now with PNG support!
www.lansrad.com - "Intelligent Solutions for Universal Problems"
www.fotokiss.com - "World's Best Auction Photo Editor"
-------------------------------------------------------------------------------------------------------