trailofbits / uthenticode

A cross-platform library for verifying Authenticode signatures
https://trailofbits.github.io/uthenticode/
MIT License
133 stars 33 forks source link

uthenticode: enforce codeSigning EKU on intermediates #92

Closed woodruffw closed 6 months ago

woodruffw commented 6 months ago

This does not change the threat model at all, since we still don't do full-chain verification. But it's strictly closer to what Authenticode says to do.