Skip to content

fix(picky): anchor Authenticode CTL check on the root certificate - #533

Draft
Mathieu Morrissette (mmorrissette-devolutions) wants to merge 2 commits into
masterfrom
fix/authenticode-ctl-root-thumbprint
Draft

Mathieu Morrissette (mmorrissette-devolutions) wants to merge 2 commits into
masterfrom
fix/authenticode-ctl-root-thumbprint

Conversation

@mmorrissette-devolutions

@mmorrissette-devolutions Mathieu Morrissette (mmorrissette-devolutions) commented Sep 28, 2026 •

Copy link
Copy Markdown

Match the CTL entry on the SHA-1 thumbprint of the root certificate, after verifying the chain up to it, instead of the issuer name hash. Roots not embedded in the signature can be provided with trusted_roots().

Breaking: signatures that don't embed their root (signtool's default) now fail with RootCertificateUnavailable unless the root is provided with trusted_roots(); follow-ups could verify the CTL's own PKCS#7 signature and add a root provider that fetches missing roots from Windows Update by thumbprint.

chatgpt-codex-connector[bot]

This comment was marked as outdated.

chatgpt-codex-connector[bot]

This comment was marked as outdated.

Match the CTL entry on the SHA-1 thumbprint of the root certificate,
after verifying the chain up to it, instead of the issuer name hash.
Add `trusted_roots()` to provide roots not embedded in the signature,
and prefer a CTL-listed root among those whose key signed the chain.
@mmorrissette-devolutions

Copy link
Copy Markdown
Author

Codex (@codex) review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 0c0f5dde94

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "Codex (@codex) review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "Codex (@codex) address that feedback".

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant