Opened 5 months ago

Last modified 9 days ago

#29614 new defect

Use SHA-256 algorithm for Windows authenticode timestamping

Reported by: gk Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-security, tbb-8.5, GeorgKoppen201907, TorBrowserTeam201907
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

We switched to using SHA-256 for the authenticode signature but we should use that hash algo for the timestamp as well (currently that's still SHA-1)

Child Tickets

Change History (14)

comment:1 Changed 5 months ago by gk

Should be not too hard to adapt our timestamping script, see: https://sourceforge.net/p/osslsigncode/support-requests/9/.

comment:2 Changed 4 months ago by gk

Keywords: TorBrowserTeam201903 added; TorBrowserTeam201902 removed

Moving my tickets to March.

comment:3 Changed 4 months ago by gk

Keywords: GeorgKoppen201903 added; GeorgKoppen201902 removed

Now for my keyword.

comment:4 Changed 4 months ago by gk

Keywords: tbb-8.5 added

Tickets on our radar for 8.5

comment:5 in reply to:  1 Changed 4 months ago by gk

Replying to gk:

Should be not too hard to adapt our timestamping script, see: https://sourceforge.net/p/osslsigncode/support-requests/9/.

Unfortunately, this did not work. I'll need to look again at the code and our patch do decouple the signing from the timestamping to figure out what goes wrong here.

comment:6 Changed 4 months ago by gk

Not to self: we likely need to adapt my patch for osslsigncode so that the -h option is available for the add command as well.

comment:7 Changed 3 months ago by gk

Keywords: TorBrowserTeam201904 added; TorBrowserTeam201903 removed

Moving tickets to April.

comment:8 Changed 3 months ago by gk

Keywords: GeorgKoppen201904 added; GeorgKoppen201903 removed

Moving my tickets for April

comment:9 Changed 2 months ago by gk

Keywords: TorBrowserTeam201905 added; TorBrowserTeam201904 removed

Moving tickets to May

comment:10 Changed 2 months ago by gk

Keywords: GeorgKoppen201905 added; GeorgKoppen201904 removed

Move my tickets.

comment:11 Changed 5 weeks ago by gk

Keywords: TorBrowserTeam201906 added; TorBrowserTeam201905 removed

Moving tickets to June

comment:12 Changed 5 weeks ago by gk

Keywords: GeorgKoppen201906 added; GeorgKoppen201905 removed

Moving my tickets to June

comment:13 Changed 2 weeks ago by gk

Keywords: GeorgKoppen201907 added; GeorgKoppen201906 removed

Moving my tickets to July.

comment:14 Changed 9 days ago by gk

Keywords: TorBrowserTeam201907 added; TorBrowserTeam201906 removed

Moving tickets to July

Note: See TracTickets for help on using tickets.