Commit 2b95e6d
committed
Ignore the expiration of certificate in SHA2 check
The purpose of this check is not to validate the chain, completely. The chain is needed so we know which certificate is the root and intermediates so we know which to validate and which not to validate. It is possible to have a valid authenticode signature if the certificate is expired but was timestamped while it was valid. In this case we still want to successfully build a chain to perform validation.
The expirely rules will be covered in the VerifyTrust check.1 parent ada54b4 commit 2b95e6d
File tree
1 file changed
+1
-0
lines changed- AuthenticodeLint/Rules
1 file changed
+1
-0
lines changedLines changed: 1 addition & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| 26 | + | |
26 | 27 | | |
27 | 28 | | |
28 | 29 | | |
| |||
0 commit comments