Opened 3 months ago

Last modified 3 weeks ago

#29614 new defect

Use SHA-256 algorithm for Windows authenticode timestamping

Reported by: gk Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-security, tbb-8.5, TorBrowserTeam201905, GeorgKoppen201905
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

We switched to using SHA-256 for the authenticode signature but we should use that hash algo for the timestamp as well (currently that's still SHA-1)

Child Tickets

Change History (10)

comment:1 Changed 3 months ago by gk

Should be not too hard to adapt our timestamping script, see: https://sourceforge.net/p/osslsigncode/support-requests/9/.

comment:2 Changed 3 months ago by gk

Keywords: TorBrowserTeam201903 added; TorBrowserTeam201902 removed

Moving my tickets to March.

comment:3 Changed 3 months ago by gk

Keywords: GeorgKoppen201903 added; GeorgKoppen201902 removed

Now for my keyword.

comment:4 Changed 3 months ago by gk

Keywords: tbb-8.5 added

Tickets on our radar for 8.5

comment:5 in reply to:  1 Changed 2 months ago by gk

Replying to gk:

Should be not too hard to adapt our timestamping script, see: https://sourceforge.net/p/osslsigncode/support-requests/9/.

Unfortunately, this did not work. I'll need to look again at the code and our patch do decouple the signing from the timestamping to figure out what goes wrong here.

comment:6 Changed 2 months ago by gk

Not to self: we likely need to adapt my patch for osslsigncode so that the -h option is available for the add command as well.

comment:7 Changed 8 weeks ago by gk

Keywords: TorBrowserTeam201904 added; TorBrowserTeam201903 removed

Moving tickets to April.

comment:8 Changed 7 weeks ago by gk

Keywords: GeorgKoppen201904 added; GeorgKoppen201903 removed

Moving my tickets for April

comment:9 Changed 3 weeks ago by gk

Keywords: TorBrowserTeam201905 added; TorBrowserTeam201904 removed

Moving tickets to May

comment:10 Changed 3 weeks ago by gk

Keywords: GeorgKoppen201905 added; GeorgKoppen201904 removed

Move my tickets.

Note: See TracTickets for help on using tickets.