A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Artifact Signing Account is giving SmartScreen at each release since march this year.
Hi
We have been using the Azure Artifiact Signing for our releases for well over a year without any problems. However, since March it seems we are having problems like many other with our releases triggering the SmartScreen. Monday the latest where a hotfix was made for a release in May. It seems like the reputation has to be build up after each release (which uses a new certificate as they are only valid for some days), this poses a major problem for us, as our enterprise customers has strict security policies so they cannot do a "run anyways".
The result for the signtool verify /pa /v for the exe in question is shown below.
Verifying: ------
Signature Index: 0 (Primary Signature)
Hash of file (sha256): 16FC5EFD61BCE1A7715372AEF51D8FF84A205D33FA90240B0DBC93C28D7B8A57
Signing Certificate Chain:
Issued to: Microsoft Identity Verification Root Certificate Authority 2020
Issued by: Microsoft Identity Verification Root Certificate Authority 2020
Expires: Sun Apr 16 20:44:40 2045
SHA1 hash: F40042E2E5F7E8EF8189FED15519AECE42C3BFA2
Issued to: Microsoft ID Verified Code Signing PCA 2021
Issued by: Microsoft Identity Verification Root Certificate Authority 2020
Expires: Tue Apr 01 22:15:20 2036
SHA1 hash: 8E750F459DAF9A79D6370DB747AD2226866AD818
Issued to: Microsoft ID Verified CS AOC CA 04
Issued by: Microsoft ID Verified Code Signing PCA 2021
Expires: Wed Mar 26 20:11:29 2031
SHA1 hash: 4C07413E5DA89A259A127E1D76F792AF239CD9D9
Issued to: Suzlon Energy A/S
Issued by: Microsoft ID Verified CS AOC CA 04
Expires: Wed Jun 24 07:15:13 2026
SHA1 hash: 4BEE2295F4D823618C9FABB1BA8E5E6563D6C74E
The signature is timestamped: Mon Jun 22 16:32:19 2026
Timestamp Verified by:
Issued to: Microsoft Identity Verification Root Certificate Authority 2020
Issued by: Microsoft Identity Verification Root Certificate Authority 2020
Expires: Sun Apr 16 20:44:40 2045
SHA1 hash: F40042E2E5F7E8EF8189FED15519AECE42C3BFA2
Issued to: Microsoft Public RSA Timestamping CA 2020
Issued by: Microsoft Identity Verification Root Certificate Authority 2020
Expires: Mon Nov 19 22:42:31 2035
SHA1 hash: 27F0ABAC2877BA255F62B389B43FF539A0FB598E
Issued to: Microsoft Public RSA Time Stamping Authority
Issued by: Microsoft Public RSA Timestamping CA 2020
Expires: Thu Jan 07 20:59:03 2027
SHA1 hash: 7587C337A84BB5BF291A58191AD102FFCDCF36BF
Successfully verified: -------
Number of files successfully Verified: 1
Number of warnings: 0
Number of errors: 0
I also submitted the file for scanning, but it didn't help the SmartScreen is still being shown. We cannot deploy this application to the Microsoft Store to avoid this. What else can be done, besides discarding the use of Azure Artifact Signing and reverting back to buying a certificate each year from a vendor ?
Artifact Signing
Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.