Windows 10: EV Code Signing Certificate and MS Defender

Discus and support EV Code Signing Certificate and MS Defender in AntiVirus, Firewalls and System Security to solve the problem; Hello I understand that applying an EV Code Signing Certificate to an exe file will overcome the screening by Windows Defender and other anti virus... Discussion in 'AntiVirus, Firewalls and System Security' started by PaulM_63, Aug 4, 2019.

  1. PaulM_63 Win User

    EV Code Signing Certificate and MS Defender


    Hello

    I understand that applying an EV Code Signing Certificate to an exe file will overcome the screening by Windows Defender and other anti virus software. Is this so? Are there any traps?

    Thanks

    :)
     
    PaulM_63, Aug 4, 2019
    #1
  2. jtraulle Win User

    Why Windows Defender SmartScreen does not show publisher name of a signed executable?

    I have purchased a Standard Code Signing certificate from Digicert and I do not understand why my executable, although signed with a certificate from a trusted CA is displayed as Unknown Publisher by Windows Defender SmartScreen.


    EV Code Signing Certificate and MS Defender Z4A3v.png


    If I disable "Check applications and files" in "Control applications and browser" of the "Windows Defender Security Center" of Windows 10, my editor name appears correctly in the "Open File - Warning security"


    EV Code Signing Certificate and MS Defender cN17d.png


    So, I'd really like to understand why the SmartScreen filter in Windows Defender still says Unknown Publisher.

    I understand that the SmartScreen filter is based on a reputation system and I do not question the actual display of the warning message (as my Code Signing certificate is not an EV one) but the fact that the name of the publisher is indicated as Unknown Publisher, whereas a valid signature is present.

    Any idea about that? I am code signing wrongly the executable?
     
    jtraulle, Aug 4, 2019
    #2
  3. Rob Koch Win User
    Defender/SmartScreen warning.

    I also recall reading that the use of an Extended Validation certificate may improve the reputation more quickly, but since this article is from the initial time of this change in 2012 I'm not certain how much of this is still applicable today.

    Along with higher cost, my understanding is that these certificates require a deeper vetting process to confirm a developer are who they claim to be, resulting in the gains discussed in the paragraph below.

    Microsoft SmartScreen & Extended Validation (EV) Code Signing Certificates

    "Detractors may claim that SmartScreen is “forcing” developers to spend money on

    certificates. It should be stressed that EV code signing certificates are not required

    to build or maintain reputation with SmartScreen. Files signed with standard code

    signing certificates and even unsigned files continue to build reputation as they

    have since Application Reputation was introduced in IE9 last year. However, the

    presence of an EV code signing certificate is a strong indicator that the file was

    signed by an entity that has passed a rigorous validation process and was signed

    with hardware which allows our systems to establish reputation for that entity more

    quickly than unsigned or non-EV code signed programs."

    Rob
     
    Rob Koch, Aug 4, 2019
    #3
Thema:

EV Code Signing Certificate and MS Defender

Loading...
  1. EV Code Signing Certificate and MS Defender - Similar Threads - Code Signing Certificate

  2. Compromised code signing certificate

    in Windows 10 Gaming
    Compromised code signing certificate: I would like to report to Microsoft that the private key of the MEDIATEK INC. certificate with the serial number 56f008e69a7c4c3feb389c66eaf58259 has had its private key compromised by bad actors and that the validity of this certificate should be revoked immediately. Where...
  3. Compromised code signing certificate

    in Windows 10 Software and Apps
    Compromised code signing certificate: I would like to report to Microsoft that the private key of the MEDIATEK INC. certificate with the serial number 56f008e69a7c4c3feb389c66eaf58259 has had its private key compromised by bad actors and that the validity of this certificate should be revoked immediately. Where...
  4. Compromised code signing certificate

    in AntiVirus, Firewalls and System Security
    Compromised code signing certificate: I would like to report to Microsoft that the private key of the MEDIATEK INC. certificate with the serial number 56f008e69a7c4c3feb389c66eaf58259 has had its private key compromised by bad actors and that the validity of this certificate should be revoked immediately. Where...
  5. Defend Smart Screen Blocking New EV Code Signing Certificate

    in AntiVirus, Firewalls and System Security
    Defend Smart Screen Blocking New EV Code Signing Certificate: We publish software that runs on Microsoft Server and Windows 10+. Recently Identrust a division of HID Global forced our company to replace our existing EV Code Signing Certificate due to some root cert issues. We received and installed the new EV Code Signing Certificate...
  6. Defend Smart Screen Blocking New EV Code Signing Certificate

    in Windows 10 Gaming
    Defend Smart Screen Blocking New EV Code Signing Certificate: We publish software that runs on Microsoft Server and Windows 10+. Recently Identrust a division of HID Global forced our company to replace our existing EV Code Signing Certificate due to some root cert issues. We received and installed the new EV Code Signing Certificate...
  7. Defend Smart Screen Blocking New EV Code Signing Certificate

    in Windows 10 Software and Apps
    Defend Smart Screen Blocking New EV Code Signing Certificate: We publish software that runs on Microsoft Server and Windows 10+. Recently Identrust a division of HID Global forced our company to replace our existing EV Code Signing Certificate due to some root cert issues. We received and installed the new EV Code Signing Certificate...
  8. Smartscreen triggers despite application signed with EV-code signing cert

    in AntiVirus, Firewalls and System Security
    Smartscreen triggers despite application signed with EV-code signing cert: Has anyone seen an issue where an application signed with an EV code signing cert still gets flagged by Windows smartscreen? I've spent hours with the support team of my certificate provider, and they are stumped on the issue. They say that everything looks good with the cert...
  9. SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate

    in AntiVirus, Firewalls and System Security
    SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate: Hello Team,I have one of my Customer sign their exe file with Digicert's EV CS Extended Validation Code SIgning Certificate a few days ago.However when we either try to download the file through Microsoft Edge or Install it, the Microsoft Defender Smartscreen flag it as...
  10. SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate

    in AntiVirus, Firewalls and System Security
    SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate: Hello Team,I have one of my Customer sign their exe file with Digicert's EV CS Extended Validation Code SIgning Certificate a few days ago.However when we either try to download the file through Microsoft Edge or Install it, the Microsoft Defender Smartscreen flag it as...