Skip to content
⌘ NSIS Forum Archive

heads-up for big changes affecting signed installers

2 posts

umeca74#

heads-up for big changes affecting signed installers

Hi, not an NSIS specific problem, but there are big changes ahead for people who digitally sign their installers with SHA1 certificates. Not many people seem to know what's going to happen from early 2016, and I bet many people reading this forum will be affected. See here for the details and what you need to do if you have a SHA1 code signing certificate

From 1/1/2016 your SHA1 signed app installer will not be trusted by windows 7 and later, and most people are oblivious. We discuss what's going to happen and what software vendors can do to prepare for SHA-256 changes in authenticode
Anders#
...and if you are using Verisign you might have to switch timestamp server: http://stackoverflow.com/questions/2...th-a-timestamp