View Full Version : Certificate Revoked ??????
NewsArchive
02-13-2017, 04:52 AM
WTF?
See attached
Dan
NewsArchive
02-13-2017, 04:53 AM
Now why would they do that? Damn these dictators.
Andre Labuschagne
NewsArchive
02-13-2017, 04:54 AM
Yup, now I can't sell and deliver anything
Dan Scott
NewsArchive
02-13-2017, 04:55 AM
>
> Now why would they do that? Damn these dictators.
>
For example, when you request a new certificate as a replacement for an old
one.
Dan's screenshot says "Valid from 9/29/2014 to 9/29/2017". This certificate
from 2014 was not SHA-2 based and so I think Dan requested a free SHA-2
replacement. Comodo issued a SHA-2 based certificate valid from 1/26/2016
to 9/30/2017. The expiration date is nearly identical, so perhaps this NEW
one replaces the OLD one (and Comodo revoked it). It's not possible to
code-sign with revoked certificates.
Friedrich
NewsArchive
02-13-2017, 04:57 AM
We have incomplete info, I guess:
1. Did this revocation message happen to an existing .exe that was
already signed with the certificate that was replaced?
or
2. Did he successfully code sign with a revoked certificate that then
showed as revoked in the file properties?
Jeff Slarve
www.jssoftware.com
Twitter free since Jan 11, 2016
I'll search help files & Google for you.
Grammar troll's, are the worse.
NewsArchive
02-13-2017, 04:58 AM
Weird thing is, I don’t have UAC on
Dan Scott
NewsArchive
02-13-2017, 04:59 AM
AND, it only happens on 1 exe out of 5
Dan Scott
NewsArchive
02-13-2017, 04:59 AM
Dan,
> AND, it only happens on 1 exe out of 5
Does it still happen if you re-sign the EXE?
--
Lee White
RPM Report Viewer.: http://www.cwaddons.com/products/rpm/
RPM Review........: http://archive.clarionmag.com/cmag/v11/v11n06rpm.html
Report Faxing.....: http://www.cwaddons.com/products/afe/
---Enroll Today---: http://CWaddons.com
Creative Reporting: http://www.CreativeReporting.com
Product Release & Update Notices
http://twitter.com/DeveloperPLUS
Windows 8 brings us "The Oval, Bumper Car, Roller Coaster of Wait!"
And, now, Windows 10 brings us "The Inch Worm, Bumper Car of Wait!"
NewsArchive
02-13-2017, 05:00 AM
Yup, tried that at least 10 times
Dan Scott
NewsArchive
02-13-2017, 05:01 AM
Better contact comodo.
You can download their current certificate revocation list here:
http://crl.comodoca.com/COMODORSACodeSigningCA.crl
Following these instructions
http://www.interfacett.com/blogs/how-to-examine-any-certificate-revocation-list-in-windows-with-certutil/
I dumped it to a text file (attached).
As a first check, I'd look to see if your cert's serial number is on their
list.
More reading:
https://www.comodo.com/repository/Validation-and-Code-Signing-Addendum-to-the-CPS.pdf
https://blogs.msdn.microsoft.com/ieinternals/2011/04/07/understanding-certificate-revocation-checks/
Jane Fleming
NewsArchive
02-13-2017, 05:02 AM
That's it for me, no code signing
Dan Scott
NewsArchive
02-13-2017, 05:04 AM
Dan,
I think you have requested a NEW certificate from Comodo and as a result,
your OLD one has been revoked.
As far as I can see, your NEW one is still valid. See attached screenshot
from one of your installs.
So IMO, you tried to use your OLD (from 2014 and not SHA-2 based)
certificate here and that causes your problem.
Friedrich
Powered by vBulletin® Version 4.2.5 Copyright © 2024 vBulletin Solutions Inc. All rights reserved.