Renewed the Windows code signing certificate for another 3 years.
contrib: Renew Windows code signing certificate #30149
pull achow101 wants to merge 1 commits into bitcoin:master from achow101:2024-win-cert-renew changing 1 files +22 −22-
achow101 commented at 3:56 AM on May 22, 2024: member
-
windeploy: Renew certificate 9f4ff1e965
-
DrahtBot commented at 3:56 AM on May 22, 2024: contributor
<!--e57a25ab6845829454e8d69fc972939a-->
The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.
<!--006a51241073e994b41acfe9ec718e94-->
Code Coverage
For detailed information about the code coverage, see the test coverage report.
<!--021abf342d371248e50ceaed478a90ca-->
Reviews
See the guideline for information on the review process.
If your review is incorrectly listed, please react with 👎 to this comment and the bot will ignore it on the next update.
- DrahtBot added the label Scripts and tools on May 22, 2024
- achow101 removed the label Scripts and tools on May 22, 2024
- achow101 added the label Needs backport (25.x) on May 22, 2024
- achow101 added the label Needs backport (26.x) on May 22, 2024
- achow101 added the label Needs backport (27.x) on May 22, 2024
- achow101 added the label Scripts and tools on May 22, 2024
-
fanquake commented at 12:33 PM on May 22, 2024: member
Diff of our cert:
--- a/a.txt +++ b/a.txt @@ -2,12 +2,12 @@ Certificate: Data: Version: 3 (0x2) Serial Number: - 0a:65:6f:75:06:a5:ef:65:36:43:16:d4:4d:3d:d2:45 + 07:34:78:e8:9d:b2:ab:78:3e:f8:d6:d0:4b:f0:41:54 Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, O=DigiCert, Inc., CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Validity - Not Before: May 24 00:00:00 2022 GMT - Not After : May 29 23:59:59 2024 GMT + Not Before: May 22 00:00:00 2024 GMT + Not After : May 31 23:59:59 2027 GMT Subject: C=US, ST=Delaware, L=Lewes, O=Bitcoin Core Code Signing LLC, CN=Bitcoin Core Code Signing LLC Subject Public Key Info: Public Key Algorithm: rsaEncryption @@ -54,6 +54,9 @@ Certificate: 68:37:E0:EB:B6:3B:F8:5F:11:86:FB:FE:61:7B:08:88:65:F4:4E:42 X509v3 Subject Key Identifier: BC:2A:54:E7:C3:C8:BA:87:EF:D2:41:C9:DD:3C:B4:60:32:84:CB:77 + X509v3 Certificate Policies: + Policy: 2.23.140.1.4.1 + CPS: http://www.digicert.com/CPS X509v3 Key Usage: critical Digital Signature X509v3 Extended Key Usage: @@ -63,12 +66,9 @@ Certificate: URI:http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl Full Name: URI:http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl - X509v3 Certificate Policies: - Policy: 2.23.140.1.4.1 - CPS: http://www.digicert.com/CPS Authority Information Access: OCSP - URI:http://ocsp.digicert.com CA Issuers - URI:http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt - X509v3 Basic Constraints: critical + X509v3 Basic Constraints: CA:FALSE Signature Algorithm: sha256WithRSAEncryption - fanquake approved
-
fanquake commented at 9:38 AM on May 23, 2024: member
ACK 9f4ff1e9659597307f62510f1885ad8da3a1d9a3
-
glozow commented at 10:36 AM on May 23, 2024: member
tested ACK 9f4ff1e96595
- fanquake merged this on May 23, 2024
- fanquake closed this on May 23, 2024
- fanquake referenced this in commit 423bd6dc68 on May 23, 2024
- fanquake removed the label Needs backport (27.x) on May 23, 2024
- glozow referenced this in commit 24c282f730 on May 23, 2024
- glozow referenced this in commit ec5ce2fb2b on May 23, 2024
- glozow referenced this in commit 6d7a1e3670 on May 24, 2024
- fanquake removed the label Needs backport (26.x) on May 28, 2024
- fanquake referenced this in commit 7a4eff2c98 on May 28, 2024
- fanquake removed the label Needs backport (25.x) on May 28, 2024
- fanquake referenced this in commit fb9890cbd5 on May 29, 2024
- fanquake referenced this in commit fccd32efe6 on May 29, 2024
-
hebasto commented at 11:20 AM on May 31, 2024: member
Backported to 27.x in #30092.
Windows 11 shows the correct data in the "Digital Signatures Details" for the
bitcoin-27.1rc1-win64-setup.exe: -
DCMTOKEN commented at 3:36 AM on August 23, 2024: none
Please approve revised
- bitcoin locked this on Aug 23, 2025