HISE Logo Forum
    • Categories
    • Register
    • Login

    Shoutout: Azure Trusted Signing

    Scheduled Pinned Locked Moved General Questions
    14 Posts 4 Posters 747 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Christoph HartC
      Christoph Hart
      last edited by

      Anybody that has ever tried to go through the code signing procedure on Windows will know how absurdly bad the experience is and paying an obscene amount of money to a random company so that your end user will not be screamed at during the installation procedure did prevent me from doing so (at least with the HISE installers).

      While the extortion feeling hasn't changed too much, the new service from Microsoft is at least cheaper (like as cheap as doing the same thing on macOS) and the procedure is somewhat reasonable, so I tried again and was rather pleased about the outcome.

      I went through this guide:

      Link Preview Image
      KoalaDocs/azure-code-signing-for-plugin-developers.md at master · koaladsp/KoalaDocs

      Useful articles for plugin developers. Contribute to koaladsp/KoalaDocs development by creating an account on GitHub.

      favicon

      GitHub (github.com)

      which took me about an hour of pasting weird strings between places but now it's setup and the HISE installers should be codesigned properly. You need to have a business with a valid tax ID for more than three years and your email must have a unique domain (my first validation was denied because I used a googlemmail account). Apart from that everything went smooth.

      d.healeyD DanHD 2 Replies Last reply Reply Quote 4
      • d.healeyD
        d.healey @Christoph Hart
        last edited by

        @Christoph-Hart Does this provide the same level as an EV cert (skipping the reputation issue)?

        Libre Wave - Freedom respecting instruments and effects
        My Patreon - HISE tutorials
        YouTube Channel - Public HISE tutorials

        Christoph HartC 1 Reply Last reply Reply Quote 0
        • DanHD
          DanH @Christoph Hart
          last edited by

          @Christoph-Hart This is useful to know, thanks.

          Currently InnoSetup 6.0.3 and LazySign (self signing tool) is working for me...

          DHPlugins / DC Breaks | Artist / Producer / DJ / Developer
          https://dhplugins.com/ | https://dcbreaks.com/
          London, UK

          1 Reply Last reply Reply Quote 0
          • Christoph HartC
            Christoph Hart @d.healey
            last edited by

            @d-healey yup, the certificate is from Microsoft so the reputation should be fine, but I'm no expert here...

            That's what I see when I inspect the signature:

            593664b5-95d1-4878-916a-b59d18086b67-image.png

            Christoph HartC d.healeyD A 3 Replies Last reply Reply Quote 0
            • Christoph HartC
              Christoph Hart @Christoph Hart
              last edited by

              Currently InnoSetup 6.0.3 and LazySign (self signing tool) is working for me...

              But does this prevent the popup in the installer? Last time I checked this didn't work (I used a self-signed certificate to sign the AAX plugin, but I couldn't get it to silence the installer warning).

              DanHD A 2 Replies Last reply Reply Quote 0
              • DanHD
                DanH @Christoph Hart
                last edited by

                @Christoph-Hart no it doesn't, but no one ever complains about that as we know. I'm assuming Azure does?

                DHPlugins / DC Breaks | Artist / Producer / DJ / Developer
                https://dhplugins.com/ | https://dcbreaks.com/
                London, UK

                Christoph HartC 1 Reply Last reply Reply Quote 0
                • d.healeyD
                  d.healey @Christoph Hart
                  last edited by

                  @Christoph-Hart I'll have to do some tests. According to the website it's just base reputation which I believe is a level below what EV provides.

                  cd5da829-08ea-4e45-8679-0449ba0506c9-image.png

                  Libre Wave - Freedom respecting instruments and effects
                  My Patreon - HISE tutorials
                  YouTube Channel - Public HISE tutorials

                  1 Reply Last reply Reply Quote 0
                  • Christoph HartC
                    Christoph Hart @DanH
                    last edited by

                    but no one ever complains about that as we know.

                    Yeah it takes a particularly annoying customer that would get vocal about this, but it certainly isn't giving the best first impression. It's not critical and I too have been raw dogging the installers on Windows for years but this is the first time that I think the cost / benefit ratio is reasonable.

                    According to the website it's just base reputation which I believe is a level below what EV provides.

                    What additional benefits do the EV certificates have? I just care about getting rid of that nasty popup, I couldn't bother less about making my software more secure lol.

                    d.healeyD 1 Reply Last reply Reply Quote 0
                    • d.healeyD
                      d.healey @Christoph Hart
                      last edited by d.healey

                      @Christoph-Hart said in Shoutout: Azure Trusted Signing:

                      What additional benefits do the EV certificates have?

                      If the signed installer doesn't have enough reputation it will be flagged by the smartscreen filter. The user will see warning messages when they try to download or run the installer.

                      This kind of thing

                      66343c4c-edd0-4b2c-9c5d-fccfda97f379-image.png

                      EV certificate allows you to bypass the reputation building stage - which must be repeated for every new version apparently.

                      Libre Wave - Freedom respecting instruments and effects
                      My Patreon - HISE tutorials
                      YouTube Channel - Public HISE tutorials

                      1 Reply Last reply Reply Quote 1
                      • A
                        aaronventure @Christoph Hart
                        last edited by

                        @Christoph-Hart said in Shoutout: Azure Trusted Signing:

                        But does this prevent the popup in the installer?

                        Submitting to the Defender analysis does, tho it takes 3 weeks. But once you build reputation (either that way or through installs, it won't ever pop up (that was my idea with having an installer that just installs the .dat files you ship with it - you're always shipping the same .exe and don't have to rebuild reputation with SmartScreen for every new patch or plugin.

                        1 Reply Last reply Reply Quote 0
                        • A
                          aaronventure @Christoph Hart
                          last edited by

                          @Christoph-Hart Did you have to go through the whole ordeal of getting a DUNS number?

                          Christoph HartC 1 Reply Last reply Reply Quote 0
                          • Christoph HartC
                            Christoph Hart @aaronventure
                            last edited by

                            @aaronventure no my Tax ID that I'm using as sole proprietor was fine.

                            DanHD 1 Reply Last reply Reply Quote 1
                            • DanHD
                              DanH @Christoph Hart
                              last edited by

                              @Christoph-Hart is this it here:

                              Link Preview Image
                              Trusted Signing—Managed Signing Services | Microsoft Azure

                              Secure your applications with a fully managed end-to-end signing service for code, documents, applications, and more with Trusted Signing from Microsoft Azure.

                              favicon

                              (azure.microsoft.com)

                              ?

                              DHPlugins / DC Breaks | Artist / Producer / DJ / Developer
                              https://dhplugins.com/ | https://dcbreaks.com/
                              London, UK

                              Christoph HartC 1 Reply Last reply Reply Quote 0
                              • Christoph HartC
                                Christoph Hart @DanH
                                last edited by

                                @DanH No, the pricing model is mentioned here:

                                https://techcommunity.microsoft.com/t5/security-compliance-and-identity/trusted-signing-is-in-public-preview/ba-p/4103457

                                Note that this is preliminary (and I think at the moment it's even free), but I find it quite reasonable.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post

                                19

                                Online

                                1.7k

                                Users

                                11.8k

                                Topics

                                102.6k

                                Posts