Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: migrate to a CA issued certificate #5893

Merged
merged 1 commit into from
Feb 24, 2024

Conversation

PastaPastaPasta
Copy link
Member

@PastaPastaPasta PastaPastaPasta commented Feb 22, 2024

Issue being fixed or feature implemented

Uses a new CA issued certificate

What was done?

Certificate changed; the issuer according to the certificate is GoGetSSL G4 CS RSA4096 SHA256 2022 CA-11 In reality, the CA is digicert and the root CA is DigiCert Trusted Root G4 and is issued to "Dash Core Group, Inc."

How Has This Been Tested?

Signed a binary with it see: https://www.virustotal.com/gui/file/a6577f3b8b474cfb1def1ea339795cb229b26d248d71f0b6f0b65e9e9ba3411b/details. I can share the binary if you'd like.

Breaking Changes

Not really any; unless someone is relying on a specific certificate.

Signature

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

8154f5a92ffe1124ad1573487f6e1842fe28eed7a455416c82fc6211253117ed  contrib/windeploy/win-codesign.cert
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKVkDYuyHioH9PCArUlJ77avoeYQFAmXWkZEACgkQUlJ77avo
eYSU2Q//fa6yzHrjW9cjsuxyRn/b+t7ry9lplzHtQDqxADxq5ANhddfurDWKOVNc
Fu3iiK1iCtdaBMDSvlAW9/nWXaJaMSqkCdExaCS63EDyItPRSwiEmCIMe1EzR1Ed
0AWrnWYIRk27huQ3RbCcnsQUEoMI3DbBMDN19ClMzyMtFiTjQfIgB0WO7OLsI785
ZXx2dqcrRYSkDd72YYfuoamJPxFXC9+kOa1Ss531w4F/86jIG+VnqVuH6L0iPkJ1
HM5jF2jLDCiU8eFN/ANsCvC65+a0nSq+xKJLeqSen0KwAPy/lBAcqY9VduvDpAyE
a6gWDhTEbYGzQicVTS3EDp0360Y0UOKixuLibzD/8Vlhk0stgEyOwoeKbNj6vRt4
MuKjAsmvh/WpuYXHmycJU1pJZ1V/udyjmpSRsr8+xB6Ww5T/epu2OJ3Yjsyny5P+
ncVtQfO18rAVIRKb6zWBygz1ITqdU23bVHApp+3pwbZTQP1ilIMRadTX7cMic6/a
eKc8jEW6BWYiXNjCOu3PPOE/P9ML537LqSg4XJXyxdemmJofzcPb1HMpngwmdQHO
jm4tOzAFwe/rdISpthED1zfgLAuWiIYNstCtzdTeDizLOfYICe8kPBjsc3zaZqCx
Cj8qlV/BqvXpua+KpuDLHa11n3amN+trNd5oOb6ewZmJqxLo4NM=
=d3Bu
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEYKz3C/cSZFBJ7m8V7+rxZoYiX2QFAmXWkZsACgkQ7+rxZoYi
X2QOOwf/YUm2TPXtrxOT7/CJVTITQa3u0XMwJ6JADuHtJaXlmA9b9ucz2cSKaFdC
noA1q8FFWbMUDM9+RkudAjhO5JCLMkJrfCK/mG2FlZrXV/61lounxyRdMerxk9qF
8/iJS1cf6t3tE4/SziMgo3uCZf5tsORIiNRxdEhBITVmDenPNTpKKGetijH7gr7o
lRHP5lNNPWH629eFqFtVORYiyvFOtSMV2PfG+lauBnm8DMoHIXC+Zs3lT6Soes+L
hxli9z+/ZGnQdHHIFIM+qcQNKIiEoWb4iUmsMK2couGk6beoWZNUmEpTjzubEfbN
QU252WZBsdGwQ/NEr5Gi4rNeUSfvig==
=hlUn
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

8154f5a92ffe1124ad1573487f6e1842fe28eed7a455416c82fc6211253117ed  win-codesign.cert
5dcc037bb56205a8744c99d1ba15e8fc7e64144ba3ce728ce57546d804469ea1  win-codesign.cert.1
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKVkDYuyHioH9PCArUlJ77avoeYQFAmXXbrAACgkQUlJ77avo
eYSItRAAtVeQDgfl2Blxya6MuvnKJiyS9W2fSfjTchUo5zmhqcbhTLcCVh9JG25T
ebpNRmf5GFzCIVDc3SRj9EuZ4SjRyf4ZcRBPq25+Q6IJUeI5S+W+v09LQ3k7nE44
g9lgHVh1KDKzxmCiEoavQ5UhND0pi9A7HreDXS6Ntc84BDgHCOAF+7tGyq6APP8y
LU35zlv6iJJcy+fCm/UspHQVYIsyShrMYNlOarK/6ZuBoCEAjPWU4L3fsaYIwxfU
6JQyhKRe3XWMcOxbb3a0ZX1wTZNsFYl5o/1guTOwH6WUPIzOdYCQEkA3+z9fNs6n
IZOzB8UdTx4Uhig8zxIlVw1EgBzvIjxbIqfBiCzKLNeEK8YFmQrmwemKtdOzPU0O
dnKDxSvQirJ/YxESJF9zyzplBIGxHluT3xTAY3JdcEYs+Xc/RKmb6eGaP5MAO8z6
lOVLbDObBMOvoPWHZaCoykGJvFvF9YXR0MpbxPtCqnpK6kTXU9z+qPDGkMLJ7pUj
X/kZneW2Mril+t7g9CEqKKQcUkdf4MoonddDGdQ2fbfrYpEJ+b5jsUbI4XkbhCwl
4KmAaBx7y1Zmxt83o2aSm1mNu5B687f8bUNOd7twE42sbsJ6w/YyKB7/JRbhIPDg
vEHn9omSA2XHGxcteFA1LBbKjDvhKsCENIY64+lwOxv8fJ4XEiE=
=TGa5
-----END PGP SIGNATURE-----

Checklist:

Go over all the following points, and put an x in all the boxes that apply.

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated relevant unit/integration/functional/e2e tests
  • I have made corresponding changes to the documentation
  • I have assigned this pull request to a milestone (for repository code-owners and collaborators only)

@PastaPastaPasta PastaPastaPasta added this to the 20.1 milestone Feb 22, 2024
Copy link

@UdjinM6 UdjinM6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

signature is ok but hash is different for me

> sha256sum contrib/windeploy/win-codesign.cert     
5dcc037bb56205a8744c99d1ba15e8fc7e64144ba3ce728ce57546d804469ea1  contrib/windeploy/win-codesign.cert

@PastaPastaPasta
Copy link
Member Author

PastaPastaPasta commented Feb 22, 2024

Very odd...

Here is the diff between the two files; they appear the same to me; maybe some metadata difference or something?

> $ diff win-codesign.cert win-codesign.cert.1 -y                                                                                                                                                                                                                     [±feat-new-cert ●]
-----BEGIN CERTIFICATE-----             |       -----BEGIN CERTIFICATE-----
MIIFejCCA2KgAwIBAgIQAlT0uBtKniPybIjyQJ1wwzANBgkqhkiG9w0BA       |       MIIFejCCA2KgAwIBAgIQAlT0uBtKniPybIjyQJ1wwzANBgkqhkiG9w0BA
MQswCQYDVQQGEwJMVjEZMBcGA1UEChMQRW5WZXJzIEdyb3VwIFNJQTEwM       |       MQswCQYDVQQGEwJMVjEZMBcGA1UEChMQRW5WZXJzIEdyb3VwIFNJQTEwM
AxMnR29HZXRTU0wgRzQgQ1MgUlNBNDA5NiBTSEEyNTYgMjAyMiBDQS0xM       |       AxMnR29HZXRTU0wgRzQgQ1MgUlNBNDA5NiBTSEEyNTYgMjAyMiBDQS0xM
MDIyMTAwMDAwMFoXDTI3MDIyMTIzNTk1OVowbjELMAkGA1UEBhMCVVMxE       |       MDIyMTAwMDAwMFoXDTI3MDIyMTIzNTk1OVowbjELMAkGA1UEBhMCVVMxE
BAgTB0FyaXpvbmExDTALBgNVBAcTBE1lc2ExHjAcBgNVBAoTFURhc2ggQ       |       BAgTB0FyaXpvbmExDTALBgNVBAcTBE1lc2ExHjAcBgNVBAoTFURhc2ggQ
cm91cCwgSW5jLjEeMBwGA1UEAxMVRGFzaCBDb3JlIEdyb3VwLCBJbmMuM       |       cm91cCwgSW5jLjEeMBwGA1UEAxMVRGFzaCBDb3JlIEdyb3VwLCBJbmMuM
KoZIzj0CAQYFK4EEACIDYgAEVfkX5+W7xjvfhkd6MIs4rRWtOeYS6ydYm       |       KoZIzj0CAQYFK4EEACIDYgAEVfkX5+W7xjvfhkd6MIs4rRWtOeYS6ydYm
XyMV77aSb2dipLpsb0c1RplEbzJIXMALa3Rm05BPFpaed81n2bf/VPnUI       |       XyMV77aSb2dipLpsb0c1RplEbzJIXMALa3Rm05BPFpaed81n2bf/VPnUI
qwMgYR+YyeIjjFs4FJm8Ew0xo4IB1DCCAdAwHwYDVR0jBBgwFoAUyfwQ7       |       qwMgYR+YyeIjjFs4FJm8Ew0xo4IB1DCCAdAwHwYDVR0jBBgwFoAUyfwQ7
vQhE7zpik+1bXpowHQYDVR0OBBYEFGOo8xDYojxv7+7/cMdufP/vG0GKM       |       vQhE7zpik+1bXpowHQYDVR0OBBYEFGOo8xDYojxv7+7/cMdufP/vG0GKM
IAQ3MDUwMwYGZ4EMAQQBMCkwJwYIKwYBBQUHAgEWG2h0dHA6Ly93d3cuZ       |       IAQ3MDUwMwYGZ4EMAQQBMCkwJwYIKwYBBQUHAgEWG2h0dHA6Ly93d3cuZ
cnQuY29tL0NQUzAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBB       |       cnQuY29tL0NQUzAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBB
gZcGA1UdHwSBjzCBjDBEoEKgQIY+aHR0cDovL2NybDMuZGlnaWNlcnQuY       |       gZcGA1UdHwSBjzCBjDBEoEKgQIY+aHR0cDovL2NybDMuZGlnaWNlcnQuY
R2V0U1NMRzRDU1JTQTQwOTZTSEEyNTYyMDIyQ0EtMS5jcmwwRKBCoECGP       |       R2V0U1NMRzRDU1JTQTQwOTZTSEEyNTYyMDIyQ0EtMS5jcmwwRKBCoECGP
Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9Hb0dldFNTTEc0Q1NSU0E0MDk2U0hBM       |       Ly9jcmw0LmRpZ2ljZXJ0LmNvbS9Hb0dldFNTTEc0Q1NSU0E0MDk2U0hBM
MkNBLTEuY3JsMIGDBggrBgEFBQcBAQR3MHUwJAYIKwYBBQUHMAGGGGh0d       |       MkNBLTEuY3JsMIGDBggrBgEFBQcBAQR3MHUwJAYIKwYBBQUHMAGGGGh0d
Y3NwLmRpZ2ljZXJ0LmNvbTBNBggrBgEFBQcwAoZBaHR0cDovL2NhY2Vyd       |       Y3NwLmRpZ2ljZXJ0LmNvbTBNBggrBgEFBQcwAoZBaHR0cDovL2NhY2Vyd
aWNlcnQuY29tL0dvR2V0U1NMRzRDU1JTQTQwOTZTSEEyNTYyMDIyQ0EtM       |       aWNlcnQuY29tL0dvR2V0U1NMRzRDU1JTQTQwOTZTSEEyNTYyMDIyQ0EtM
CQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAgEAkr3cuc0ctBEVxksDW       |       CQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAgEAkr3cuc0ctBEVxksDW
bsnqGoXFsFJrRJ9JU21d4hPVtjT3+z6xJrzIpYTt0r7AZab6NmyNmpyU5       |       bsnqGoXFsFJrRJ9JU21d4hPVtjT3+z6xJrzIpYTt0r7AZab6NmyNmpyU5
aWlu9LVjC4jZbvjVXwjGYMNUUbBOY+qw+xDup4uCYEiHMeRfAZjV2dAVI       |       aWlu9LVjC4jZbvjVXwjGYMNUUbBOY+qw+xDup4uCYEiHMeRfAZjV2dAVI
zceSAiW0Hl7gJBl1PeJyRhU3BylTPW6Pb0b+IDvEBWzlYN6F74Ak8qWeX       |       zceSAiW0Hl7gJBl1PeJyRhU3BylTPW6Pb0b+IDvEBWzlYN6F74Ak8qWeX
R4hSJ8jE7u3edTVx9UPAIAAxNTlTj3RY+HoZR57jfeGyyH1WUpTd9XSCp       |       R4hSJ8jE7u3edTVx9UPAIAAxNTlTj3RY+HoZR57jfeGyyH1WUpTd9XSCp
5nslOTTL4/Eh2joxNqH3tv0RNfQGBd3yTXPuTNcVJTguyR7N24HFubZRs       |       5nslOTTL4/Eh2joxNqH3tv0RNfQGBd3yTXPuTNcVJTguyR7N24HFubZRs
H1eigjFULSym8G8os3G2B9b33voUu4DYTte2xnE5DI2zoYfrcsUhKoX0F       |       H1eigjFULSym8G8os3G2B9b33voUu4DYTte2xnE5DI2zoYfrcsUhKoX0F
jLBUdrXnMWtvW5eCfMjoB4DQoKkrU9PjWpKXE7ze3kI/FFS6AzEcVOA7A       |       jLBUdrXnMWtvW5eCfMjoB4DQoKkrU9PjWpKXE7ze3kI/FFS6AzEcVOA7A
HvQwQHdBoYjwGYoP6fA6jrgejflkxb+SAgQWVw1c4tgiGeSXbg2OiiTbt       |       HvQwQHdBoYjwGYoP6fA6jrgejflkxb+SAgQWVw1c4tgiGeSXbg2OiiTbt
5uzO3YHAKZgWw1kYq+xfZHafpDdoiD9b5LcXwSNtuwdkzodM0NvCeHGb5       |       5uzO3YHAKZgWw1kYq+xfZHafpDdoiD9b5LcXwSNtuwdkzodM0NvCeHGb5
cRV00cF3KgzJeSHheIh2IXeO0Vob9FG6vDCncD3msZ0pBUXN9bhqzmblf       |       cRV00cF3KgzJeSHheIh2IXeO0Vob9FG6vDCncD3msZ0pBUXN9bhqzmblf
a3cV9NbtlicAJ4MEyIs=                            |       a3cV9NbtlicAJ4MEyIs=
-----END CERTIFICATE-----               |       -----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----                                             -----BEGIN CERTIFICATE-----
MIIGoTCCBImgAwIBAgIQB4Q9rQHBFcJ07kGnKCJGeTANBgkqhkiG9w0BA               MIIGoTCCBImgAwIBAgIQB4Q9rQHBFcJ07kGnKCJGeTANBgkqhkiG9w0BA
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDV               MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDV
d3cuZGlnaWNlcnQuY29tMSEwHwYDVQQDExhEaWdpQ2VydCBUcnVzdGVkI               d3cuZGlnaWNlcnQuY29tMSEwHwYDVQQDExhEaWdpQ2VydCBUcnVzdGVkI
RzQwHhcNMjIwNjIzMDAwMDAwWhcNMzIwNjIyMjM1OTU5WjBaMQswCQYDV               RzQwHhcNMjIwNjIzMDAwMDAwWhcNMzIwNjIyMjM1OTU5WjBaMQswCQYDV
VjEZMBcGA1UEChMQRW5WZXJzIEdyb3VwIFNJQTEwMC4GA1UEAxMnR29HZ               VjEZMBcGA1UEChMQRW5WZXJzIEdyb3VwIFNJQTEwMC4GA1UEAxMnR29HZ
RzQgQ1MgUlNBNDA5NiBTSEEyNTYgMjAyMiBDQS0xMIICIjANBgkqhkiG9               RzQgQ1MgUlNBNDA5NiBTSEEyNTYgMjAyMiBDQS0xMIICIjANBgkqhkiG9
AAOCAg8AMIICCgKCAgEArR70B7JDZoqiZ3cllQql+BbWKeRXySzvUodAb               AAOCAg8AMIICCgKCAgEArR70B7JDZoqiZ3cllQql+BbWKeRXySzvUodAb
WLdtcX/If6Syf+2M3inDavc+MxIXnKrQ9MYW70gfJLAQH1gTGTtDS3zk9               WLdtcX/If6Syf+2M3inDavc+MxIXnKrQ9MYW70gfJLAQH1gTGTtDS3zk9
+67/mRc2vpsSEO/bNXQosFDMBqJ2qAyu5qmXw6ShBMUelMigYd2mrU+91               +67/mRc2vpsSEO/bNXQosFDMBqJ2qAyu5qmXw6ShBMUelMigYd2mrU+91
n2E5kBavjfBay7OhYemBBliU4LMcsNXwAoQn4LRHGZHbXICu6rqrJB7Vu               n2E5kBavjfBay7OhYemBBliU4LMcsNXwAoQn4LRHGZHbXICu6rqrJB7Vu
Se091l6c57Djsa896sdAs1o8CvPtyr9l+qYlr3fGEXwDsnEq0+PzzNHBy               Se091l6c57Djsa896sdAs1o8CvPtyr9l+qYlr3fGEXwDsnEq0+PzzNHBy
Jv3pOBQp2EnpuN3aBX7QcWQUJByqD1twbelSK4VSMLzu4a1I4XISSWWHU               Jv3pOBQp2EnpuN3aBX7QcWQUJByqD1twbelSK4VSMLzu4a1I4XISSWWHU
74ief06D+xDb/e1PTLShb5guXc3daeB8RUdKecFpmEG1vst0RZtJ6eh/Z               74ief06D+xDb/e1PTLShb5guXc3daeB8RUdKecFpmEG1vst0RZtJ6eh/Z
dMrJnSY29H+/nVS19zhAVG+h/q9S0S2U/8RDk7sDsRoNkuMNuShi/UggV               dMrJnSY29H+/nVS19zhAVG+h/q9S0S2U/8RDk7sDsRoNkuMNuShi/UggV
zx3iU6FPkx7dD/GUH+AfSBZRsbSytIN7jgJ8EhYCrZjY4ZE5fHGiwEMG4               zx3iU6FPkx7dD/GUH+AfSBZRsbSytIN7jgJ8EhYCrZjY4ZE5fHGiwEMG4
XNG+pNmfPkMIFQC9JyLszPXJCj/MbSHFoPOS9/5dHE5B0HXvoyhgxtgnc               XNG+pNmfPkMIFQC9JyLszPXJCj/MbSHFoPOS9/5dHE5B0HXvoyhgxtgnc
FLcKg+yQNrgsVpSM0TYME9JB9np9PkFfCs4khmqjtq9OpMG6Ktv8cuHvf               FLcKg+yQNrgsVpSM0TYME9JB9np9PkFfCs4khmqjtq9OpMG6Ktv8cuHvf
AwEAAaOCAVkwggFVMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEF               AwEAAaOCAVkwggFVMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEF
yMtrf70IRO86YpPtW16aMB8GA1UdIwQYMBaAFOzX44LScV1kTN8uZz/nu               yMtrf70IRO86YpPtW16aMB8GA1UdIwQYMBaAFOzX44LScV1kTN8uZz/nu
MA4GA1UdDwEB/wQEAwIBhjATBgNVHSUEDDAKBggrBgEFBQcDAzB3BggrB               MA4GA1UdDwEB/wQEAwIBhjATBgNVHSUEDDAKBggrBgEFBQcDAzB3BggrB
AQRrMGkwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvb               AQRrMGkwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvb
BgEFBQcwAoY1aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0RpZ2lDZ               BgEFBQcwAoY1aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL0RpZ2lDZ
c3RlZFJvb3RHNC5jcnQwQwYDVR0fBDwwOjA4oDagNIYyaHR0cDovL2Nyb               c3RlZFJvb3RHNC5jcnQwQwYDVR0fBDwwOjA4oDagNIYyaHR0cDovL2Nyb
aWNlcnQuY29tL0RpZ2lDZXJ0VHJ1c3RlZFJvb3RHNC5jcmwwHAYDVR0gB               aWNlcnQuY29tL0RpZ2lDZXJ0VHJ1c3RlZFJvb3RHNC5jcmwwHAYDVR0gB
BgVngQwBAzAIBgZngQwBBAEwDQYJKoZIhvcNAQELBQADggIBAAvbCteyH               BgVngQwBAzAIBgZngQwBBAEwDQYJKoZIhvcNAQELBQADggIBAAvbCteyH
RLO/snsISZyeLcqy8DRJ35eh6xvD5ux2dG/uSXPhhqiU/JEXO5oobla3b               RLO/snsISZyeLcqy8DRJ35eh6xvD5ux2dG/uSXPhhqiU/JEXO5oobla3b
ngy/YpobQrrCP61Jo8IbX5afl4C5JoCxq5rBIaNW/pRokaeywv9dHYvEg               ngy/YpobQrrCP61Jo8IbX5afl4C5JoCxq5rBIaNW/pRokaeywv9dHYvEg
+WcdeNsUbwa61o/XjnUhh8GLmwLBHegg6I8HGlc/aX1zM2Dt5HNDuj14N               +WcdeNsUbwa61o/XjnUhh8GLmwLBHegg6I8HGlc/aX1zM2Dt5HNDuj14N
QlALgx7pP7GcevFtBVY9T9ojIflVKvZS9abq6AMnaHllVIf/nDF3qn4KQ               QlALgx7pP7GcevFtBVY9T9ojIflVKvZS9abq6AMnaHllVIf/nDF3qn4KQ
JmuResii9LLVUB/L2G9REtJiUiD8iH5CIwtVdKW2Ut6dEFrCmmnxKK/Hy               JmuResii9LLVUB/L2G9REtJiUiD8iH5CIwtVdKW2Ut6dEFrCmmnxKK/Hy
7VSP7oLrdPunpJbj1kaRFx/iQIjXUY2y22XIQkRHt/15dGJcJAPnkFSXz               7VSP7oLrdPunpJbj1kaRFx/iQIjXUY2y22XIQkRHt/15dGJcJAPnkFSXz
bWP5jqStgDfhNubeZkGBYaXcWV+S0wyloA52/gOkJxLeIjcrpHC2ibkvC               bWP5jqStgDfhNubeZkGBYaXcWV+S0wyloA52/gOkJxLeIjcrpHC2ibkvC
gC2S7d0arPpV4nyvxsJzSFkDW3+xZiwwfaYfIvHb7EdYbI3NijxFuGwLG               gC2S7d0arPpV4nyvxsJzSFkDW3+xZiwwfaYfIvHb7EdYbI3NijxFuGwLG
dcxNf0GzlfdrwxqBY8GTotpKEPlMhIdHvIwxRwCiXkyPqfBDxP5qr6Iyx               dcxNf0GzlfdrwxqBY8GTotpKEPlMhIdHvIwxRwCiXkyPqfBDxP5qr6Iyx
yANrY7dBEbbI5IQTZmWOkhDn5yKDsL8qmryz8mtVLd/9nDhS7jUPEJeh2               yANrY7dBEbbI5IQTZmWOkhDn5yKDsL8qmryz8mtVLd/9nDhS7jUPEJeh2
585/mRAGlE5D2WnlcqByJDgxAi85                                            585/mRAGlE5D2WnlcqByJDgxAi85
-----END CERTIFICATE-----                                               -----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----                                             -----BEGIN CERTIFICATE-----
MIIFkDCCA3igAwIBAgIQBZsbV56OITLiOQe9p3d1XDANBgkqhkiG9w0BA               MIIFkDCCA3igAwIBAgIQBZsbV56OITLiOQe9p3d1XDANBgkqhkiG9w0BA
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDV               MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDV
d3cuZGlnaWNlcnQuY29tMSEwHwYDVQQDExhEaWdpQ2VydCBUcnVzdGVkI               d3cuZGlnaWNlcnQuY29tMSEwHwYDVQQDExhEaWdpQ2VydCBUcnVzdGVkI
RzQwHhcNMTMwODAxMTIwMDAwWhcNMzgwMTE1MTIwMDAwWjBiMQswCQYDV               RzQwHhcNMTMwODAxMTIwMDAwWhcNMzgwMTE1MTIwMDAwWjBiMQswCQYDV
UzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlna               UzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlna
Y29tMSEwHwYDVQQDExhEaWdpQ2VydCBUcnVzdGVkIFJvb3QgRzQwggIiM               Y29tMSEwHwYDVQQDExhEaWdpQ2VydCBUcnVzdGVkIFJvb3QgRzQwggIiM
SIb3DQEBAQUAA4ICDwAwggIKAoICAQC/5pBzaN675F1KPDAiMGkz7MKnJ               SIb3DQEBAQUAA4ICDwAwggIKAoICAQC/5pBzaN675F1KPDAiMGkz7MKnJ
ithZwuEppz1Yq3aaza57G4QNxDAf8xukOBbrVsaXbR2rsnnyyhHS5F/WB               ithZwuEppz1Yq3aaza57G4QNxDAf8xukOBbrVsaXbR2rsnnyyhHS5F/WB
xp4VpX6+n6lXFllVcq9ok3DCsrp1mWpzMpTREEQQLt+C8weE5nQ7bXHiL               xp4VpX6+n6lXFllVcq9ok3DCsrp1mWpzMpTREEQQLt+C8weE5nQ7bXHiL
ySAdYyktzuxeTsiT+CFhmzTrBcZe7FsavOvJz82sNEBfsXpm7nfISKhmV               ySAdYyktzuxeTsiT+CFhmzTrBcZe7FsavOvJz82sNEBfsXpm7nfISKhmV
DCu3T6cw2Vbuyntd463JT17lNecxy9qTXtyOj4DatpGYQJB5w3jHtrHEt               DCu3T6cw2Vbuyntd463JT17lNecxy9qTXtyOj4DatpGYQJB5w3jHtrHEt
jdjUN6QuBX2I9YI+EJFwq1WCQTLX2wRzKm6RAXwhTNS8rhsDdV14Ztk6M               jdjUN6QuBX2I9YI+EJFwq1WCQTLX2wRzKm6RAXwhTNS8rhsDdV14Ztk6M
CNdaSaTC5qmgZ92kJ7yhTzm1EVgX9yRcRo9k98FpiHaYdj1ZXUJ2h4mXa               CNdaSaTC5qmgZ92kJ7yhTzm1EVgX9yRcRo9k98FpiHaYdj1ZXUJ2h4mXa
EhtmmnTK3kse5w5jrubU75KSOp493ADkRSWJtppEGSt+wJS00mFt6zPZx               EhtmmnTK3kse5w5jrubU75KSOp493ADkRSWJtppEGSt+wJS00mFt6zPZx
fRyVw4/3IbKyEbe7f/LVjHAsQWCqsWMYRJUadmJ+9oCw++hkpjPRiQfhv               fRyVw4/3IbKyEbe7f/LVjHAsQWCqsWMYRJUadmJ+9oCw++hkpjPRiQfhv
uKZ3AeEPlAwhHbJUKSWJbOUOUlFHdL4mrLZBdd56rF+NP8m800ERElvlE               uKZ3AeEPlAwhHbJUKSWJbOUOUlFHdL4mrLZBdd56rF+NP8m800ERElvlE
chYiCd98THU/Y+whX8QgUWtvsauGi0/C1kVfnSD8oR7FwI+isX4KJpn15               chYiCd98THU/Y+whX8QgUWtvsauGi0/C1kVfnSD8oR7FwI+isX4KJpn15
9dmpsh3lGwIDAQABo0IwQDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/               9dmpsh3lGwIDAQABo0IwQDAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/
hjAdBgNVHQ4EFgQU7NfjgtJxXWRM3y5nP+e6mK4cD08wDQYJKoZIhvcNA               hjAdBgNVHQ4EFgQU7NfjgtJxXWRM3y5nP+e6mK4cD08wDQYJKoZIhvcNA
ggIBALth2X2pbL4XxJEbw6GiAI3jZGgPVs93rnD5/ZpKmbnJeFwMDF/k5               ggIBALth2X2pbL4XxJEbw6GiAI3jZGgPVs93rnD5/ZpKmbnJeFwMDF/k5
SV1EY+CtnJYYZhsjDT156W1r1lT40jzBQ0CuHVD1UvyQO7uYmWlrx8Gnq               SV1EY+CtnJYYZhsjDT156W1r1lT40jzBQ0CuHVD1UvyQO7uYmWlrx8Gnq
+SeuMIW59mdNOj6PWTkiU0TryF0Dyu1Qen1iIQqAyHNm0aAFYF/opbSnr               +SeuMIW59mdNOj6PWTkiU0TryF0Dyu1Qen1iIQqAyHNm0aAFYF/opbSnr
fFqK1qI4mfN4i/RN0iAL3gTujJtHgXINwBQy7zBZLq7gcfJW5GqXb5JQb               fFqK1qI4mfN4i/RN0iAL3gTujJtHgXINwBQy7zBZLq7gcfJW5GqXb5JQb
sjYUegbyJLkJEVDXCLG4iXqEI2FCKeWjzaIgQdfRnGTZ6iahixTXTBmyU               sjYUegbyJLkJEVDXCLG4iXqEI2FCKeWjzaIgQdfRnGTZ6iahixTXTBmyU
cCOGDErcgdLMMpSEDQgJlxxPwO5rIHQw0uA5NBCFIRUBCOhVMt5xSdkoF               cCOGDErcgdLMMpSEDQgJlxxPwO5rIHQw0uA5NBCFIRUBCOhVMt5xSdkoF
0XWs0Mr7QbhDparTwwVETyw2m+L64kW4I1NsBm9nVX9GtUw/bihaeSbSp               0XWs0Mr7QbhDparTwwVETyw2m+L64kW4I1NsBm9nVX9GtUw/bihaeSbSp
4u1Ki7wb/UdKDd9nZn6yW0HQO+T0O/QEY+nvwlQAUaCKKsnOeMzV6ocEG               4u1Ki7wb/UdKDd9nZn6yW0HQO+T0O/QEY+nvwlQAUaCKKsnOeMzV6ocEG
r/OSmbaz5mEP0oUA51Aa5BuVnRmhuZyxm7EAHu/QD09CbMkKvO5D+jpxp               r/OSmbaz5mEP0oUA51Aa5BuVnRmhuZyxm7EAHu/QD09CbMkKvO5D+jpxp
/YldvIViHTLSoCtU7ZpXwdv6EM8Zt4tKG48BtieVU+i2iW1bvGjUI+iLU               /YldvIViHTLSoCtU7ZpXwdv6EM8Zt4tKG48BtieVU+i2iW1bvGjUI+iLU
gKDWHrO8Dw9TdSmq6hN35N6MgSGtBxBHEa2HPQfRdbzP82Z+                        gKDWHrO8Dw9TdSmq6hN35N6MgSGtBxBHEa2HPQfRdbzP82Z+
-----END CERTIFICATE-----                                               -----END CERTIFICATE-----
                                                                                                 

Anyhow; after comparing the two files are the same based on this x509 output

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            02:54:f4:b8:1b:4a:9e:23:f2:6c:88:f2:40:9d:70:c3
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=LV, O=EnVers Group SIA, CN=GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1
        Validity
            Not Before: Feb 21 00:00:00 2024 GMT
            Not After : Feb 21 23:59:59 2027 GMT
        Subject: C=US, ST=Arizona, L=Mesa, O=Dash Core Group, Inc., CN=Dash Core Group, Inc.
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub:
                    04:55:f9:17:e7:e5:bb:c6:3b:df:86:47:7a:30:8b:
                    38:ad:15:ad:39:e6:12:eb:27:58:98:f3:d7:a8:8b:
                    87:5f:23:15:ef:b6:92:6f:67:62:a4:ba:6c:6f:47:
                    35:46:99:44:6f:32:48:5c:c0:0b:6b:74:66:d3:90:
                    4f:16:96:9e:77:cd:67:d9:b7:ff:54:f9:d4:22:de:
                    90:78:be:d6:ab:03:20:61:1f:98:c9:e2:23:8c:5b:
                    38:14:99:bc:13:0d:31
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                C9:FC:10:EF:50:C8:CB:6B:7F:BD:08:44:EF:3A:62:93:ED:5B:5E:9A
            X509v3 Subject Key Identifier: 
                63:A8:F3:10:D8:A2:3C:6F:EF:EE:FF:70:C7:6E:7C:FF:EF:1B:41:8A
            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.4.1
                  CPS: http://www.digicert.com/CPS
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage: 
                Code Signing
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://crl3.digicert.com/GoGetSSLG4CSRSA4096SHA2562022CA-1.crl
                Full Name:
                  URI:http://crl4.digicert.com/GoGetSSLG4CSRSA4096SHA2562022CA-1.crl
            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com
                CA Issuers - URI:http://cacerts.digicert.com/GoGetSSLG4CSRSA4096SHA2562022CA-1.crt
            X509v3 Basic Constraints: 
                CA:FALSE
    Signature Algorithm: sha256WithRSAEncryption
    Signature Value:
        92:bd:dc:b9:cd:1c:b4:11:15:c6:4b:03:59:9d:a7:75:c6:24:
        6e:c9:ea:1a:85:c5:b0:52:6b:44:9f:49:53:6d:5d:e2:13:d5:
        b6:34:f7:fb:3e:b1:26:bc:c8:a5:84:ed:d2:be:c0:65:a6:fa:
        36:6c:8d:9a:9c:94:e4:12:36:db:e6:e9:69:69:6e:f4:b5:63:
        0b:88:d9:6e:f8:d5:5f:08:c6:60:c3:54:51:b0:4e:63:ea:b0:
        fb:10:ee:a7:8b:82:60:48:87:31:e4:5f:01:98:d5:d9:d0:15:
        23:0c:b5:58:b2:3f:cd:c7:92:02:25:b4:1e:5e:e0:24:19:75:
        3d:e2:72:46:15:37:07:29:53:3d:6e:8f:6f:46:fe:20:3b:c4:
        05:6c:e5:60:de:85:ef:80:24:f2:a5:9e:5c:55:4c:ff:85:68:
        47:88:52:27:c8:c4:ee:ed:de:75:35:71:f5:43:c0:20:00:31:
        35:39:53:8f:74:58:f8:7a:19:47:9e:e3:7d:e1:b2:c8:7d:56:
        52:94:dd:f5:74:82:a7:ea:cd:35:b8:2a:e6:7b:25:39:34:cb:
        e3:f1:21:da:3a:31:36:a1:f7:b6:fd:11:35:f4:06:05:dd:f2:
        4d:73:ee:4c:d7:15:25:38:2e:c9:1e:cd:db:81:c5:b9:b6:51:
        b2:64:c9:5f:6c:97:1f:57:a2:82:31:54:2d:2c:a6:f0:6f:28:
        b3:71:b6:07:d6:f7:de:fa:14:bb:80:d8:4e:d7:b6:c6:71:39:
        0c:8d:b3:a1:87:eb:72:c5:21:2a:85:f4:14:df:e7:f8:ae:d1:
        8c:b0:54:76:b5:e7:31:6b:6f:5b:97:82:7c:c8:e8:07:80:d0:
        a0:a9:2b:53:d3:e3:5a:92:97:13:bc:de:de:42:3f:14:54:ba:
        03:31:1c:54:e0:3b:01:19:af:39:6b:e1:1e:f4:30:40:77:41:
        a1:88:f0:19:8a:0f:e9:f0:3a:8e:b8:1e:8d:f9:64:c5:bf:92:
        02:04:16:57:0d:5c:e2:d8:22:19:e4:97:6e:0d:8e:8a:24:db:
        b5:11:83:6e:f8:c9:e6:ec:ce:dd:81:c0:29:98:16:c3:59:18:
        ab:ec:5f:64:76:9f:a4:37:68:88:3f:5b:e4:b7:17:c1:23:6d:
        bb:07:64:ce:87:4c:d0:db:c2:78:71:9b:e6:9e:b5:8e:1a:b8:
        71:15:74:d1:c1:77:2a:0c:c9:79:21:e1:78:88:76:21:77:8e:
        d1:5a:1b:f4:51:ba:bc:30:a7:70:3d:e6:b1:9d:29:05:45:cd:
        f5:b8:6a:ce:66:e5:7e:98:dd:82:22:ac:6b:77:15:f4:d6:ed:
        96:27:00:27:83:04:c8:8b
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKVkDYuyHioH9PCArUlJ77avoeYQFAmXXbo0ACgkQUlJ77avo
eYQ/hA//VDwN9WAfD0rbXhBRM3dV/FjjG0nEHJMG3G4PGxXPxdLaBe9W7JXQOUvh
gb4k6gQ7zTCUuDvP9p3nCKJUgw1Cee3iHTk3SHM4GDJw2pRiYE0GqQhgwrZBPfTW
5vrxRc1H0+6HZMVC9ZXV8j6rTd+zQqBd2OW1Z57FuCZvDNffIM0h1Ey7QmjfUkAN
ONFTRm+o0DiiRPWPWlXk76eqSaDB/3gqEA5Zw1Dt32t4F4bIHDGQZQrYIGZ0GmBq
/WRQsjX3wzALKUnABT6rUuVEwYFz2yoD1fo85/jRVyioI243J28UD8skq5qX1JTG
5pEbKwegrCY4rKimYuu4h1d6zORlMxrEzFPi2ZfDEfSiuZX7jk2NhybKEXqgue3c
yxD7AQ+3iJBDeMpqVRAtTlvNAbMEFlgkcQfrFzJ2HGRBZoQ7oDA2L9nBftWDrCNp
ESV7l9t+ZcFV/KXAFnnDReBX708GOJATlh47ibptw22XmoRfDGPbKZPVh1boKRdV
6+My4MAPbjYurglAQ0dgE2CMP/Zi7AF3zz8qU68qprNxmY6+cpzslfoQ/DtTdS+Y
m86bSPvzVLTraa9LUU2BToMhk+9vq5LibGyuAQpj9NZdPNM9XlG3K50c5fMsmssR
8Hl816MbKxfGUOpWbPu5KFbJX2wNVzy6YbXbYDqjL0FBeL5YEM4=
=33Mw
-----END PGP SIGNATURE-----

so here is a sig on both hashes as they both appear correct

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

8154f5a92ffe1124ad1573487f6e1842fe28eed7a455416c82fc6211253117ed  win-codesign.cert
5dcc037bb56205a8744c99d1ba15e8fc7e64144ba3ce728ce57546d804469ea1  win-codesign.cert.1
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKVkDYuyHioH9PCArUlJ77avoeYQFAmXXbrAACgkQUlJ77avo
eYSItRAAtVeQDgfl2Blxya6MuvnKJiyS9W2fSfjTchUo5zmhqcbhTLcCVh9JG25T
ebpNRmf5GFzCIVDc3SRj9EuZ4SjRyf4ZcRBPq25+Q6IJUeI5S+W+v09LQ3k7nE44
g9lgHVh1KDKzxmCiEoavQ5UhND0pi9A7HreDXS6Ntc84BDgHCOAF+7tGyq6APP8y
LU35zlv6iJJcy+fCm/UspHQVYIsyShrMYNlOarK/6ZuBoCEAjPWU4L3fsaYIwxfU
6JQyhKRe3XWMcOxbb3a0ZX1wTZNsFYl5o/1guTOwH6WUPIzOdYCQEkA3+z9fNs6n
IZOzB8UdTx4Uhig8zxIlVw1EgBzvIjxbIqfBiCzKLNeEK8YFmQrmwemKtdOzPU0O
dnKDxSvQirJ/YxESJF9zyzplBIGxHluT3xTAY3JdcEYs+Xc/RKmb6eGaP5MAO8z6
lOVLbDObBMOvoPWHZaCoykGJvFvF9YXR0MpbxPtCqnpK6kTXU9z+qPDGkMLJ7pUj
X/kZneW2Mril+t7g9CEqKKQcUkdf4MoonddDGdQ2fbfrYpEJ+b5jsUbI4XkbhCwl
4KmAaBx7y1Zmxt83o2aSm1mNu5B687f8bUNOd7twE42sbsJ6w/YyKB7/JRbhIPDg
vEHn9omSA2XHGxcteFA1LBbKjDvhKsCENIY64+lwOxv8fJ4XEiE=
=TGa5
-----END PGP SIGNATURE-----

Copy link

@UdjinM6 UdjinM6 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ACK

@PastaPastaPasta PastaPastaPasta requested a review from knst February 23, 2024 17:46
Copy link
Collaborator

@knst knst left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

hashes matched, pgp signatures is pasta's indeed.

$ openssl x509 -in contrib/windeploy/win-codesign.cert -text
...
            Not Before: Feb 21 00:00:00 2024 GMT
            Not After : Feb 21 23:59:59 2027 GMT
...
        Subject: C = US, ST = Arizona, L = Mesa, O = "Dash Core Group, Inc.", CN = "Dash Core Group, Inc."

seems as cert is valid too, though I don't know how to test it.

@PastaPastaPasta PastaPastaPasta merged commit e9f1a4b into dashpay:develop Feb 24, 2024
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants