PDA

View Full Version : Replacing Comodo Certificate



NewsArchive
08-31-2015, 05:51 AM
Hi all
I purchased a 3 year certificate in Jan 2014 from Comodo through
Lindersoft's discount store. I thought you may be interested in my recent
experience.
I logged in using the Lindersoft credentials that come in your subscription
emails, and then into my own Comodo account.
I clicked on the chat button and asked if I needed to purchase a new
certificate to support the new encryption.
I was politely told to simply find my purchase and click the "replace"
button - but stay on line and tell them when I had done this.
It took a few seconds.
I was then transferred to the "validation department" who asked me to wait
for a couple of minutes, and then re-issued a new certificate with no
further questions.
The old one has apparently been revoked and I mustn't use it after another
14 days.
The new one imported into Firefox with no problem, and then exported ok
although it did so as a .P12 file which I couldn't make work in SB8 until I
imported into IE and re-exported.
(I first tried in Win10/Edge but was told by the chat person that this would
likely not work).
In any case, it cost nothing and took less than 20 minutes.
The new certificate appears to work in SB8, but signs with SHA1 encryption.

The moral of the story - I did not need to do anything particular regarding
re-establishing a reputation because the certificate was still in-date, and
I had logged in through the 2 stage Lindersoft/Comodo web sites.

I have put off the hoop jumping until 2017 and saved some money in the
process. Not that it's very expensive if you are a Lindersoft customer...

Cheers
Dave Beggs

NewsArchive
08-31-2015, 05:52 AM
Thanks Dave, for your experience, I did the same after you.
Now I have downloaded certificate zip file with 4 crt files within? Appreciate
any help what you did from there on?
Many thanks
Darko

NewsArchive
08-31-2015, 05:52 AM
Thanks for sharing this interesting information, Dave !!!

Friedrich

NewsArchive
08-31-2015, 07:57 AM
Seems like this zip file I downloaded is redundant as I did "collected" my
certificate through Firefox and exported as .p12 and .pfx
Tried to put this new one within one of my SB script and no one complain. I can
see my exe file is signed with new code certificate
despite it still shows sha1 version

Thanks
Darko

NewsArchive
09-01-2015, 01:48 AM
To sign with SHA2 (or to dual-sign both SHA1 and SHA2), you'll need to
specify using SB's "#pragma CODESIGN_SHA".
There's also a new SB pragma for specifying the type of timestamp server.

AND... only newer versions of signtool support SHA2 signing. (I think the
Windows 8 and later SDKs do.)

http://www.lindersoft.com/forums/showthread.php?46550-Comodo-cert-steps&p=83327#post83327

- jf