Windows 10: Smartscreen triggers despite application signed with EV-code signing cert

Discus and support Smartscreen triggers despite application signed with EV-code signing cert in AntiVirus, Firewalls and System Security to solve the problem; Has anyone seen an issue where an application signed with an EV code signing cert still gets flagged by Windows smartscreen? I've spent hours with the... Discussion in 'AntiVirus, Firewalls and System Security' started by Yodite, Jul 4, 2021.

  1. Yodite Win User

    Smartscreen triggers despite application signed with EV-code signing cert


    Has anyone seen an issue where an application signed with an EV code signing cert still gets flagged by Windows smartscreen? I've spent hours with the support team of my certificate provider, and they are stumped on the issue. They say that everything looks good with the cert and the signing. I tried signing a small test installer just to validate it's not application specific, or related to the way I'm packaging my application, and got the same issue. I reformatted the machine where I built packaged the application, so there's no chance of any virus or malware.In Microsoft Edge, the message t

    :)
     
    Yodite, Jul 4, 2021
    #1
  2. Rob Koch Win User

    Defender/SmartScreen warning.

    I also recall reading that the use of an Extended Validation certificate may improve the reputation more quickly, but since this article is from the initial time of this change in 2012 I'm not certain how much of this is still applicable today.

    Along with higher cost, my understanding is that these certificates require a deeper vetting process to confirm a developer are who they claim to be, resulting in the gains discussed in the paragraph below.

    Microsoft SmartScreen & Extended Validation (EV) Code Signing Certificates

    "Detractors may claim that SmartScreen is “forcing” developers to spend money on

    certificates. It should be stressed that EV code signing certificates are not required

    to build or maintain reputation with SmartScreen. Files signed with standard code

    signing certificates and even unsigned files continue to build reputation as they

    have since Application Reputation was introduced in IE9 last year. However, the

    presence of an EV code signing certificate is a strong indicator that the file was

    signed by an entity that has passed a rigorous validation process and was signed

    with hardware which allows our systems to establish reputation for that entity more

    quickly than unsigned or non-EV code signed programs."

    Rob
     
    Rob Koch, Jul 4, 2021
    #2
  3. jtraulle Win User
    Why Windows Defender SmartScreen does not show publisher name of a signed executable?

    I have purchased a Standard Code Signing certificate from Digicert and I do not understand why my executable, although signed with a certificate from a trusted CA is displayed as Unknown Publisher by Windows Defender SmartScreen.


    Smartscreen triggers despite application signed with EV-code signing cert Z4A3v.png


    If I disable "Check applications and files" in "Control applications and browser" of the "Windows Defender Security Center" of Windows 10, my editor name appears correctly in the "Open File - Warning security"


    Smartscreen triggers despite application signed with EV-code signing cert cN17d.png


    So, I'd really like to understand why the SmartScreen filter in Windows Defender still says Unknown Publisher.

    I understand that the SmartScreen filter is based on a reputation system and I do not question the actual display of the warning message (as my Code Signing certificate is not an EV one) but the fact that the name of the publisher is indicated as Unknown Publisher, whereas a valid signature is present.

    Any idea about that? I am code signing wrongly the executable?
     
    jtraulle, Jul 4, 2021
    #3
  4. Smartscreen triggers despite application signed with EV-code signing cert

    Discord Voice App: Is It Safe?

    EV Code Signing Certificates | DigiCert.com

     
    TairikuOkami, Jul 4, 2021
    #4
Thema:

Smartscreen triggers despite application signed with EV-code signing cert

Loading...
  1. Smartscreen triggers despite application signed with EV-code signing cert - Similar Threads - Smartscreen triggers despite

  2. EV Signed Application prompted as a Virus in Windows Defender

    in Windows 10 Gaming
    EV Signed Application prompted as a Virus in Windows Defender: Hello, Microsoft Windows Defender keeps flagging my application as malicious even though it's signed with an EV certificate. This is really bad as users can not download an use the app, I also paid money and went trough verification process just to get this sorted out. Yet...
  3. EV Signed Application prompted as a Virus in Windows Defender

    in Windows 10 Software and Apps
    EV Signed Application prompted as a Virus in Windows Defender: Hello, Microsoft Windows Defender keeps flagging my application as malicious even though it's signed with an EV certificate. This is really bad as users can not download an use the app, I also paid money and went trough verification process just to get this sorted out. Yet...
  4. Maintain trust of SmartScreen as you move from EV to Regular Code Sign

    in Windows 10 Software and Apps
    Maintain trust of SmartScreen as you move from EV to Regular Code Sign: Our company is releasing a desktop application and wants to move from EV Code Signing HW to Regular Code Signing SW. Is there any way to maintain trust of Microsoft SmartScreen filter and avoid building reputation by downloading/installing the app organically?Thank you....
  5. Maintain trust of SmartScreen as you move from EV to Regular Code Sign

    in Windows 10 Gaming
    Maintain trust of SmartScreen as you move from EV to Regular Code Sign: Our company is releasing a desktop application and wants to move from EV Code Signing HW to Regular Code Signing SW. Is there any way to maintain trust of Microsoft SmartScreen filter and avoid building reputation by downloading/installing the app organically?Thank you....
  6. SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate

    in AntiVirus, Firewalls and System Security
    SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate: Hello Team,I have one of my Customer sign their exe file with Digicert's EV CS Extended Validation Code SIgning Certificate a few days ago.However when we either try to download the file through Microsoft Edge or Install it, the Microsoft Defender Smartscreen flag it as...
  7. SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate

    in AntiVirus, Firewalls and System Security
    SmartScreen warning on a exe file though it is signed by Digicert EV CS certificate: Hello Team,I have one of my Customer sign their exe file with Digicert's EV CS Extended Validation Code SIgning Certificate a few days ago.However when we either try to download the file through Microsoft Edge or Install it, the Microsoft Defender Smartscreen flag it as...
  8. Digital signing cert validity

    in Windows 10 Network and Sharing
    Digital signing cert validity: Why is it when I download Windows 10 Media Creator from microsoft.com/en-ca/software… and then do a Right click on the file properties | Seclect digital signatures | Click on General tab and View Certificate here it shows valid from 7/12/2018 to 8/8/2019 [ATTACH]...
  9. EV Code Signing Certificate and MS Defender

    in AntiVirus, Firewalls and System Security
    EV Code Signing Certificate and MS Defender: Hello I understand that applying an EV Code Signing Certificate to an exe file will overcome the screening by Windows Defender and other anti virus software. Is this so? Are there any traps? Thanks...
  10. SmartScreen, despite being off, is triggered by certain programs

    in AntiVirus, Firewalls and System Security
    SmartScreen, despite being off, is triggered by certain programs: I have SmartScreen turned off, but it is still interfering with at least two programs on my system. While the SmartScreen warning doesn't actually come up, the Task Manager reveals it is indeed running. Is there a way to figure out why SmartScreen is being triggered? 125136