contrib: Renew Windows code signing certificate #30149

pull achow101 wants to merge 1 commits into bitcoin:master from achow101:2024-win-cert-renew changing 1 files +22 −22
  1. achow101 commented at 3:56 am on May 22, 2024: member
    Renewed the Windows code signing certificate for another 3 years.
  2. windeploy: Renew certificate 9f4ff1e965
  3. DrahtBot commented at 3:56 am on May 22, 2024: contributor

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    Code Coverage

    For detailed information about the code coverage, see the test coverage report.

    Reviews

    See the guideline for information on the review process.

    Type Reviewers
    ACK fanquake, glozow

    If your review is incorrectly listed, please react with 👎 to this comment and the bot will ignore it on the next update.

  4. DrahtBot added the label Scripts and tools on May 22, 2024
  5. achow101 removed the label Scripts and tools on May 22, 2024
  6. achow101 added the label Needs backport (25.x) on May 22, 2024
  7. achow101 added the label Needs backport (26.x) on May 22, 2024
  8. achow101 added the label Needs backport (27.x) on May 22, 2024
  9. achow101 added the label Scripts and tools on May 22, 2024
  10. fanquake commented at 12:33 pm on May 22, 2024: member

    Diff of our cert:

     0--- a/a.txt
     1+++ b/a.txt
     2@@ -2,12 +2,12 @@ Certificate:
     3     Data:
     4         Version: 3 (0x2)
     5         Serial Number:
     6-            0a:65:6f:75:06:a5:ef:65:36:43:16:d4:4d:3d:d2:45
     7+            07:34:78:e8:9d:b2:ab:78:3e:f8:d6:d0:4b:f0:41:54
     8         Signature Algorithm: sha256WithRSAEncryption
     9         Issuer: C=US, O=DigiCert, Inc., CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
    10         Validity
    11-            Not Before: May 24 00:00:00 2022 GMT
    12-            Not After : May 29 23:59:59 2024 GMT
    13+            Not Before: May 22 00:00:00 2024 GMT
    14+            Not After : May 31 23:59:59 2027 GMT
    15         Subject: C=US, ST=Delaware, L=Lewes, O=Bitcoin Core Code Signing LLC, CN=Bitcoin Core Code Signing LLC
    16         Subject Public Key Info:
    17             Public Key Algorithm: rsaEncryption
    18@@ -54,6 +54,9 @@ Certificate:
    19                 68:37:E0:EB:B6:3B:F8:5F:11:86:FB:FE:61:7B:08:88:65:F4:4E:42
    20             X509v3 Subject Key Identifier: 
    21                 BC:2A:54:E7:C3:C8:BA:87:EF:D2:41:C9:DD:3C:B4:60:32:84:CB:77
    22+            X509v3 Certificate Policies: 
    23+                Policy: 2.23.140.1.4.1
    24+                  CPS: http://www.digicert.com/CPS
    25             X509v3 Key Usage: critical
    26                 Digital Signature
    27             X509v3 Extended Key Usage: 
    28@@ -63,12 +66,9 @@ Certificate:
    29                   URI:http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl
    30                 Full Name:
    31                   URI:http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl
    32-            X509v3 Certificate Policies: 
    33-                Policy: 2.23.140.1.4.1
    34-                  CPS: http://www.digicert.com/CPS
    35             Authority Information Access: 
    36                 OCSP - URI:http://ocsp.digicert.com
    37                 CA Issuers - URI:http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt
    38-            X509v3 Basic Constraints: critical
    39+            X509v3 Basic Constraints: 
    40                 CA:FALSE
    41     Signature Algorithm: sha256WithRSAEncryption
    
  11. fanquake approved
  12. fanquake commented at 9:38 am on May 23, 2024: member
    ACK 9f4ff1e9659597307f62510f1885ad8da3a1d9a3
  13. glozow commented at 10:36 am on May 23, 2024: member
    tested ACK 9f4ff1e96595
  14. fanquake merged this on May 23, 2024
  15. fanquake closed this on May 23, 2024

  16. fanquake referenced this in commit 423bd6dc68 on May 23, 2024
  17. fanquake removed the label Needs backport (27.x) on May 23, 2024
  18. fanquake commented at 12:30 pm on May 23, 2024: member
    Backported to 27.x in #30092.
  19. glozow referenced this in commit 24c282f730 on May 23, 2024
  20. glozow commented at 2:17 pm on May 23, 2024: member
    Backport for 26.x in #29899
  21. glozow referenced this in commit ec5ce2fb2b on May 23, 2024
  22. glozow referenced this in commit 6d7a1e3670 on May 24, 2024
  23. fanquake removed the label Needs backport (26.x) on May 28, 2024
  24. fanquake referenced this in commit 7a4eff2c98 on May 28, 2024
  25. fanquake removed the label Needs backport (25.x) on May 28, 2024
  26. fanquake commented at 3:22 pm on May 28, 2024: member
    Backported to 25.x in #30184.
  27. fanquake referenced this in commit fb9890cbd5 on May 29, 2024
  28. fanquake referenced this in commit fccd32efe6 on May 29, 2024
  29. hebasto commented at 11:20 am on May 31, 2024: member

    Backported to 27.x in #30092.

    Windows 11 shows the correct data in the “Digital Signatures Details” for the bitcoin-27.1rc1-win64-setup.exe:

    image_2024-05-31_12-18-32


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2024-07-03 10:13 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me