keybase / keybase/client

Windows Binary Verification - Outdated Info?

Open
#25,283 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
9.2k
Forks
1.3k
Avg merge
12h 58m
Merged PRs (30d)
56

Description

Hello Keybase. I have a suspicion that a cert has been updated but the docs are incorrect.

On the 'our-code-signing-key' page of the Keyboase Book I see:
Windows Codesigning Certificate Thumbprint eb187c8cbf63d8ca0dfb3cba97e8e310fc3fde52

When I use signtool.exe verify /pa /v keybase_setup_amd64.msi it comes back as a successful verification but it doesn't match the SHA1 for any of the items in the Signing Certificate Chain (C01851A26810556DE01191A869B888F723C8186A, 8FB28DD3CFFA5D286E7C718AA907CB4F9B1767C2, and DDFB16CD4931C973A2037D3FC83A4D7D775D05E4).

The book hasn't been updated since before the Zoom acquisition, but the cert is issued to Zoom Video Communications, Inc.., so it seems likely that the published info may be out of date?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Keybase Book's our-code-signing-key page and its source file D-docs/02-server/02-our-code-signing-key.md. Compare the published thumbprint with the certificate chain reported by signtool.exe for keybase_setup_amd64.msi. Done means the documentation accurately reflects the current Windows signing certificate information.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.