Windows Binary Verification - Outdated Info?
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 9.2k
- Forks
- 1.3k
- Avg merge
- 12h 58m
- Merged PRs (30d)
- 56
Description
Hello Keybase. I have a suspicion that a cert has been updated but the docs are incorrect.
On the 'our-code-signing-key' page of the Keyboase Book I see:
Windows Codesigning Certificate Thumbprint eb187c8cbf63d8ca0dfb3cba97e8e310fc3fde52
When I use signtool.exe verify /pa /v keybase_setup_amd64.msi it comes back as a successful verification but it doesn't match the SHA1 for any of the items in the Signing Certificate Chain (C01851A26810556DE01191A869B888F723C8186A, 8FB28DD3CFFA5D286E7C718AA907CB4F9B1767C2, and DDFB16CD4931C973A2037D3FC83A4D7D775D05E4).
The book hasn't been updated since before the Zoom acquisition, but the cert is issued to Zoom Video Communications, Inc.., so it seems likely that the published info may be out of date?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Keybase Book's our-code-signing-key page and its source file D-docs/02-server/02-our-code-signing-key.md. Compare the published thumbprint with the certificate chain reported by signtool.exe for keybase_setup_amd64.msi. Done means the documentation accurately reflects the current Windows signing certificate information.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100