Skip to content

Fix verification result on timestamp failure - #510

Merged
mtrojnar merged 1 commit into
mtrojnar:masterfrom
olszomal:fix-timestamp-verification-status
Sep 30, 2026
Merged

mtrojnar merged 1 commit into
mtrojnar:masterfrom
olszomal:fix-timestamp-verification-status

Conversation

@olszomal

Copy link
Copy Markdown
Collaborator

Pull Request Type

  • Bug fix
  • New feature
  • Code style / formatting / renaming
  • Refactoring (no functional or API changes)
  • Build / CI related changes
  • Documentation
  • Other (please describe):

Related Issue

Fixes #509

Current Behavior

A valid Authenticode signature may still verify successfully while the signing certificate is currently valid, even if timestamp verification fails. The timestamp is primarily used to establish that the signature existed while the signing certificate was valid, allowing it to remain verifiable after the certificate expires.

New Behavior

Verification fails when timestamp verification fails, unless timestamp verification is explicitly disabled with -ignore-timestamp.

Scope of Changes

  • Propagate timestamp verification failures to the overall verification result.
  • Add regression tests for an untrusted TSA and -ignore-timestamp.

Testing

  • Existing tests
  • New tests added
  • Manual testing

Additional Notes

This change affects only the overall verification result; the Authenticode signature and timestamp verification results are still reported separately.

License Declaration

  • I hereby agree to license my contribution under the project's license.

Propagate timestamp verification failures to the overall verification
result and add regression tests, while preserving -ignore-timestamp
behavior.

Signed-off-by: olszomal <Malgorzata.Olszowka@stunnel.org>
@mtrojnar

Copy link
Copy Markdown
Owner

It's an interesting edge case: the current behavior seems technically correct, while the new behavior seems desirable at least for validating our own signatures. What does signtool do in this case?

@mtrojnar
mtrojnar merged commit bf7533d into mtrojnar:master Sep 30, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

osslsigncode verify exits with code 0 for failed timestamp server signature verification

2 participants