dotnet / dotnet/sign

Once we have signed dlls, what do we need to change to verify them?

Open
#1,056 1 comment 0 reactions 0 assignees View on GitHub
area-verification feature-request Priority:3
Dominant language
C#
Stars
581
Forks
116
Avg merge
1d 2h
Merged PRs (30d)
8

Description

Im having trouble finding information on this because it used to work differently in dotnet framework

Signing works fine, secops love it blah blah

But from an application perspective, a signed exe doesnt verify that all dlls it’s using are signed for example… is there a modern guide on how to do that?

Contributor guide

No contributing guide indexed for this repository

Research direction

No repository file or test is identified. Start by locating the current Authenticode and signing documentation, then investigate how an application can verify signatures on the DLLs it uses. Done means a modern guide that explains whether and how applications can verify every relevant DLL.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.