Re[6]: Новое в подписи драйверов на Windows 10
От: okman Беларусь https://searchinform.ru/
Дата: 23.07.15 06:17
Оценка: 1 (1)
Здравствуйте, Vicul, Вы писали:

V>Короче, только что пообщался с ними в чате, на Висте и 7 все будет пучком. EV работает с SHA2, а чтобы виста и 7 это поняли

V>нужен устанавливать патч

V>

V>Devon J.: [11:24:41 PM] Hello! How are you today?
V>Victor: [11:24:41 PM] Hello, I have a question about EV Code Signing Certificate. I will use it for signing my drivers for Win10 (x86/x64). But I have too drivers for other Windows. Can I use EV for signing Win 7 and Vista or should still purchase Code Signing Certificate too?
V>Devon J.: [11:24:49 PM] Hello
V>[11:25:35 PM] You can use the certificate to sign the drivers for use on Windows 7, Vista however will be an issue due to it not supporting SHA2 signatures.
V>Victor: [11:27:00 PM] So, do I need to purchase two certificates?
V>Devon J.: [11:27:35 PM] No, all new code signing certificates are issued out as SHA2 certificates.
V>Victor: [11:30:55 PM] Sorry, if I sign a driver, for example, for Vista by EV, then my user will have a problem, because Vista supports only SHA1? Is true?
V>Devon J.: [11:31:31 PM] Correct
V>Victor: [11:32:53 PM] So I need two certificates: EV and Code Signing. Is it true?
V>Devon J.: [11:34:16 PM] No, all new code signing certificates are issued out as SHA2. Microsoft is mandating that all new CS certificates are SHA2. If they wanted Vista to have SHA2 support, they could push out a patch for it.
V>Victor: [11:37:41 PM] ok, does Win 7 have that problem with SHA2, or I need a patch there too?
V>Devon J.: [11:38:40 PM] Microsoft pushed out a patch for SHA2 code signing certificates for Windows 7 back in March. The hotfix is listed here: https://technet.microsoft.com/en-us/library/security/3033929.aspx


Читаем то, что написано мелким шрифтом:

Microsoft Security Advisory 3033929
https://technet.microsoft.com/en-us/library/security/3033929.aspx

Availability of SHA-2 Code Signing Support for Windows 7 and Windows Server 2008 R2

Microsoft is announcing the reissuance of an update for all supported editions of Windows 7 and
Windows Server 2008 R2 to add support for SHA-2 signing and verification functionality. This update
supersedes the 2949927 update that was rescinded on October 17, 2014 to address issues that some
customers experienced after installation. As with the original release, Windows 8, Windows 8.1,
Windows Server 2012, Windows Server 2012 R2, Windows RT, and Windows RT 8.1 do not require this update
because SHA-2 signing and verification functionality is already included in these operating systems.
This update is not available for Windows Server 2003, Windows Vista, or Windows Server 2008.

Так что на поддержку Vista и Server 2003/2008 нас заставляют положить болт.
 
Подождите ...
Wait...
Пока на собственное сообщение не было ответов, его можно удалить.