Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions NEWS.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@
- fixed Cygwin compilation by not passing ELF-specific linker flags
- fixed MSI MsiDigitalSignatureEx digest ordering during signing and verification
- fixed verification to report failure when timestamp verification fails
- added multiple timestamp support: `add` preserves existing timestamps and
`-timestamp-all` requires every specified Authenticode/RFC 3161 server
- verification now tries all timestamps and accepts any trusted timestamp for
which the Authenticode signature also validates at the timestamp's time

### 2.14 (2026.07.20)

Expand Down
14 changes: 14 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -118,6 +118,20 @@ or if you want to add a timestamp as well:
-t http://timestamp.digicert.com \
-in yourapp.exe -out yourapp-signed.exe
```
To require multiple timestamps, use `-timestamp-all` with repeated `-ts` or
`-t` options (both protocols may be combined):
```
osslsigncode add -timestamp-all \
-ts https://tsa1.example.com/ -ts https://tsa2.example.com/ \
-in yourapp-signed.exe -out yourapp-multistamped.exe
```
Every requested server must succeed. Without `-timestamp-all`, repeated URLs
remain fallback servers, stopping after the first success. `add` preserves
existing timestamps. Verification succeeds if at least one trusted timestamp
and the signing certificate/signature validate at that timestamp's time;
invalid alternatives do not invalidate a valid pair. Use `-ignore-timestamp`
to verify at the requested/current time instead.

You can use a certificate and key stored in a PKCS#12 container:
```
osslsigncode sign -pkcs12 <pkcs12-file> -pass <pkcs12-password> \
Expand Down
10 changes: 10 additions & 0 deletions cmake/CMakeTest.cmake
Original file line number Diff line number Diff line change
Expand Up @@ -424,6 +424,16 @@ if(Python3_FOUND AND NOT cryptography_error)

### Sign with Time-Stamp Authority ###

# Self-contained loopback TSA and DER fixtures; checks exit status AND
# diagnostics for multiple, mixed, untrusted and malformed timestamps.
add_test(NAME "multiple_timestamps"
COMMAND ${Python3_EXECUTABLE} "${CMAKE_CURRENT_SOURCE_DIR}/tests/multiple_timestamps.py"
${OSSLSIGNCODE} "${CMAKE_CURRENT_SOURCE_DIR}/tests/files/unsigned.exe")
set_tests_properties("multiple_timestamps" PROPERTIES
ENVIRONMENT "HTTP_PROXY=;http_proxy=;HTTPS_PROXY=;https_proxy=;ALL_PROXY=;all_proxy="
TIMEOUT 120)
list(APPEND ALL_TESTS "multiple_timestamps")

# Sign with the RFC3161 Time-Stamp Authority
set(pem_certs "cert" "expired" "revoked")
foreach(ext ${extensions_all})
Expand Down
Loading
Loading