Welcome, Guest. Please login or register.
Did you miss your activation email?
May 24, 2013, 11:37:49 AM

Login with username, password and session length

663952 Posts
70617 Topics
145247 Members

Latest Member: justcamchar

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Business / Enterprise Security Products & Services
| |-+  Digital Certificates
| | |-+  Code Signing Certificate
| | | |-+  Signtool verification issue
« previous next »
Pages: [1] Go Down Print
Author Topic: Signtool verification issue  (Read 29881 times)
smallest
Newbie
*
Offline Offline

Posts: 1


« on: February 17, 2008, 05:59:17 PM »

I got the certificate today, and exported it from Internet Explorer into a .PFX file, password-protected. No problems.

I downloaded the latest Micrsoft Dev SDK for Vista (to get the latest version of Signtool.exe). I signed a test file with the following command:

D:\Progs>signtool.exe sign /f our.pfx /p [my cert password] /t http://timestamp.comodoca.com/authenticode testfile.dll

That gives the following output:

--
Done Adding Additional Store
Successfully signed and timestamped: testfile.dll
--

So, that looks fine. Then, to verify, I run:

D:\Progs>signtool.exe verify /a /v testfile.dll

that gives the following output:

--
Verifying: testfile.dll
Unable to verify this file using a catalog.
SHA1 hash of file: EDC32B6C13164A164CC161DC56CCC746F33546A0
SignTool Error: A certificate chain processed, but terminated in a root
certificate which is not trusted by the trust provider.
Signing Certificate Chain:
Issued to: UTN-USERFirst-Object
Issued by: UTN-USERFirst-Object
Expires: 7/9/2019 1:40:36 PM
SHA1 hash: E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46

Issued to: Smaller Animals Software, Inc
Issued by: UTN-USERFirst-Object
Expires: 2/16/2009 6:59:59 PM
SHA1 hash: 5E1293B0F89DBB781173DEEDDD323F87E14377ED

The signature is timestamped: 2/17/2008 3:59:04 PM
Timestamp Verified by:
Issued to: UTN-USERFirst-Object
Issued by: UTN-USERFirst-Object
Expires: 7/9/2019 1:40:36 PM
SHA1 hash: E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46

Issued to: Comodo Time Stamping Signer
Issued by: UTN-USERFirst-Object
Expires: 5/16/2010 6:59:59 PM
SHA1 hash: 95B2B8E34EB2CB768144ED07433EF0A3AFCAEEC0

SignTool Error: File not valid: testfile.dll

Number of files successfully Verified: 0
Number of warnings: 0
Number of errors: 1
--

I've run the root update and installed the Comodo Code Signing CA.

Any ideas what's going on ?
Logged
Anthony Nel
Newbie
*
Offline Offline

Posts: 19



« Reply #1 on: March 28, 2008, 05:02:27 AM »

Hi,

This is a known error and is due to the fact that this command line tool supplied by Microsoft does not use a comprehensive CA certificate list for verification. You will find that the signed file that you have will function correctly and be trusted.
« Last Edit: April 04, 2008, 05:48:22 AM by Anthony Nel » Logged

Kind Regards
Anthony Nel
Tech Support
Darin
Newbie
*
Offline Offline

Posts: 1


« Reply #2 on: July 17, 2008, 01:29:45 PM »

I am having a similar verification issue with signtool.  Do you have any further information about this limitation in signtool?  How about a KB article reference?

Thank you.
Logged
LucasBarlow
Newbie
*
Offline Offline

Posts: 1


« Reply #3 on: August 13, 2008, 09:50:15 AM »

I noticed if I use the /pa or the /kp paramaters it will verify correctly.
Is there someone that can explain this or let me know which, if either, of these options is the "correct" way to do it?
Thanks.
Logged
vijayvbaskar
Newbie
*
Offline Offline

Posts: 1


« Reply #4 on: March 23, 2010, 07:40:22 AM »

Hi I am also getting the same problem.

Hi smallest,  did ur problem get solved.

If solved, Please tell how u solved it.
Logged
MgKg
Newbie
*
Offline Offline

Posts: 1


« Reply #5 on: April 07, 2010, 11:11:48 PM »

heyyy bros ...  Cheesy  i have a code signing pfx file but i don't knw how to use and how to sign my exe file.
plz share me your knowledge. thz alottttttttttttt
i already installed Microsoft SDK. plz .. help me  Cheesy Cheesy Cheesy Cheesy
Logged
tauzinger
Newbie
*
Offline Offline

Posts: 1


« Reply #6 on: April 22, 2010, 10:44:05 AM »

Here is what I used, your mileage may vary:
signtool sign /f mycertificate.pfx /p mypassword /t http://timestamp.verisign.com/scripts/timestamp.dll /d mycompany myactivexcontrol.cab
Logged
anon2012
Newbie
*
Offline Offline

Posts: 2


« Reply #7 on: January 29, 2012, 06:10:21 AM »

I downloaded the latest Micrsoft Dev SDK for Vista (to get the latest version of Signtool.exe). [...]
to verify, I run:

D:\Progs>signtool.exe verify /a /v testfile.dll

that gives the following output:

[...]
SignTool Error: A certificate chain processed, but terminated in a root
certificate which is not trusted by the trust provider.
The verification with signtool.exe should succeed with the option /pa (instead of /a) because Comodo's certificate cannot be used to sign Kernel mode drivers.
« Last Edit: January 29, 2012, 06:26:32 AM by anon2012 » Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.046 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com