hippie68 / gogcheck

Bash script that verifies your GOG offline installers' authenticity and checksums. Made to scan large collections.
46 stars 2 forks source link

New digital signature serial number? #7

Open k0zyrev opened 3 months ago

k0zyrev commented 3 months ago

I've stumbled upon a recent upload (1 month old) which has signature's serial number not previously seen 0bad5d6bf5ce1ef257dafb8b75be92b2 - can anyone check if it's authentic? For some reason the issuer is called "Sectigo RSA Time Stamping Signer #4" instead of digicert, so it's a bit suspicious.

https://lenp.pardesicat.xyz/G21DoCu0

Ammako commented 3 months ago

Doesn't check out to me?

image

ghost commented 2 months ago

Verified that atleast the two installers for Resident Evil 1 and 2 are using this serial. Time to add 0bad5d6bf5ce1ef257dafb8b75be92b2 to the verified list?

Name GOG sp. z o.o Status Valid Issuer DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Valid From 12:00 AM 03/07/2024 Valid To 11:59 PM 03/19/2025 Valid Usage Code Signing Algorithm sha256RSA Thumbprint AED404C86C5A1327B267355AB201A1197E0DAA66 Serial Number 0B AD 5D 6B F5 CE 1E F2 57 DA FB 8B 75 BE 92 B2