<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Innovative Software Solutions &#187; digital signature</title>
	<atom:link href="http://blog.ksoftware.net/tag/digital-signature/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ksoftware.net</link>
	<description></description>
	<lastBuildDate>Fri, 02 Dec 2011 03:24:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>What is Authenticode (Code Signing)?</title>
		<link>http://blog.ksoftware.net/2011/07/what-is-authenticode/</link>
		<comments>http://blog.ksoftware.net/2011/07/what-is-authenticode/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 22:47:25 +0000</pubDate>
		<dc:creator>Mitchell Vincent</dc:creator>
				<category><![CDATA[Code Signing/Authenticode]]></category>
		<category><![CDATA[authenticode]]></category>
		<category><![CDATA[code signing]]></category>
		<category><![CDATA[digital signature]]></category>
		<category><![CDATA[digital signatures]]></category>
		<category><![CDATA[ksign]]></category>
		<category><![CDATA[unknown publisher]]></category>

		<guid isPermaLink="false">http://blog.ksoftware.net/?p=5</guid>
		<description><![CDATA[Authenticode™ is a technology developed by Microsoft that, according to them : While not guaranteeing bug-free code, Authenticode identifies the publisher of signed software and verifies that it hasn&#8217;t been tampered with, before users download software to their PCs - &#8230; <a href="http://blog.ksoftware.net/2011/07/what-is-authenticode/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Authenticode™ is a technology developed by Microsoft that, according to them :</p>
<blockquote><p>While not guaranteeing bug-free code, Authenticode identifies the publisher of signed software and verifies that it hasn&#8217;t been tampered with, before users download software to their PCs -<a title="Microsoft's Definition of Authenticode" href="http://technet.microsoft.com/en-us/library/cc750035.aspx" target="_blank"> <span id="main" style="visibility: visible;"><span id="search" style="visibility: visible;"><cite>technet.microsoft.com/en-us/library/cc750035.aspx</cite></span></span></a></p></blockquote>
<p>Authenticode is commonly referred to as Code Signing because a &#8220;digital signature&#8221; is attached to .EXE and other files that is used to determine if the file has been modified since being &#8220;signed&#8221; by the publisher.</p>
<p>The way most users have run across Authenticode is likely by downloading a piece of software and seeing a rather nasty &#8220;Unknown Publisher&#8221; warning from the web browser (or Windows). <strong>Does this look familiar to anyone?</strong></p>
<p><strong><img class="alignnone size-full wp-image-28" title="Example of an unknown publisher warning in Internet Explorer" src="http://blog.ksoftware.net/wp-content/uploads/2009/07/unknown_publisher.PNG" alt="Example of an unknown publisher warning in Internet Explorer" width="465" height="232" /><br />
</strong></p>
<p>That is an example of an Unknown Publisher download warning in Windows Vista.</p>
<p>Now an example of the same warning, but for a file that has been digitally signed (by K Software) :</p>
<p><img class="alignnone size-full wp-image-27" title="An example of a known publisher - valid code signing certificate used" src="http://blog.ksoftware.net/wp-content/uploads/2009/07/known_publisher.PNG" alt="An example of a known publisher - valid code signing certificate used" width="464" height="211" /></p>
<p>If you click on the linked K Software text you can see the details of the certificate :</p>
<p><img class="alignnone size-full wp-image-29" title="Example of a certificate details page" src="http://blog.ksoftware.net/wp-content/uploads/2009/07/certificate_details.PNG" alt="Example of a certificate details page" width="409" height="477" /></p>
<p>Note the &#8220;This Digital Signature is OK&#8221; message. If you don&#8217;t see that on the certificate details page then you should not run it as the file has been modified since the publisher signed it (it could have a virus or contain some other sort of malware).</p>
<h2>What Authenticode is Not</h2>
<p>Authenticode (Code Signing) is not a guarantee that the software that has been digitally signed is bug free or even virus/malware free. All a digital signature says is &#8220;this file has not been modified since it was signed by the publisher&#8221;. Having said that it is worth noting that obtaining a <a title="K Software Sells Comodo Code Signing Certificates" href="http://codesigning.ksoftware.net" target="_blank">code signing certificate</a> is not free and that companies or individuals that apply for a code signing certificate do have to pay a fee and do have to prove their identity to the company that issues the certificate.</p>
<p><a href="http://codesigning.ksoftware.net" target="_blank"><img class="size-full wp-image-32 alignleft" title="Comodo Code Signing Certificate Partner" src="http://blog.ksoftware.net/wp-content/uploads/2009/07/ComodoPartnerLogo.gif" alt="Comodo Code Signing Certificate Partner" width="169" height="56" /></a></p>
<p>K Software is an authorized Comodo reseller and offers Comodo Code Signing Certificates at a significant discount. <a href="http://codesigning.ksoftware.net" target="_blank">Read more</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ksoftware.net/2011/07/what-is-authenticode/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

