wazuh-packages icon indicating copy to clipboard operation
wazuh-packages copied to clipboard

The signature in MSI package does not contain a timestamp

Open rafabailon opened this issue 1 year ago • 0 comments

Description

In certificates check it has been found that the signature in MSI package does not contain a timestamp.

Found in Scheduled certificates review - 2024 Monthly #01

image

Details

When it comes to digital signatures, timestamping refers to the process of including an electronic timestamp in your signature to possibly extend the validity of the signing certificate.

Therefore, if a certificate includes a timestamp, it will validate the certificate by verifying the signature against the time it was signed, and not the time you are running the software. And if not and a certificate has expired, then not having a digital signature timestamp will essentially block the application from being used.

Steps to Reproduce

To reproduce the error you must follow the following steps:

image

image

Tasks

  • [ ] Add timestamp to the MSI Package Signature
  • [ ] Check that the MSI Package Signature has timestamp

rafabailon avatar Jan 08 '24 16:01 rafabailon