Signing VSTO Code with EV Certificate on Visual Studio 2017

Viewed 2798

I have a VSTO program in Visual Studio 2017. In order to make the install process run more smoothly when I publish via ClickOnce and host the files on the web, I bought an EV Certificate from DigiCert.

This is what I bought - https://www.digicert.com/code-signing/ev-code-signing/

So I waited a couple days, got my USB token, set everything up and now when I sign the app with my fancy new certificate... the install flat-out fails.

The error the user gets is: Customized Functionality in this application will not work because the certificate used to sign the deployment manifest for AppName or its location is not trusted. Contact your administrator for further assistance.

I contacted DigiCert for tech support and they basically said that this is an error with Visual Studio 2017 and the Operating System.

I then called Entrust to see if they could confirm since they also have the EV Certificates: https://www.entrust.com/code-signing-certificates/#ev-code-signing-certificates

Turns out I guess until you buy one, they can't answer the question. They just kindof say "buy it and try it and if it doesn't work we'll give you your money back."

How is it possible that nobody knows how to sign an install from Visual Studio?

I would love to be able to sign this install and get it to work.

2 Answers

What to sign and why

  1. Visual Studio relies on SignTool to sign the Setup.exe of the App it builds. This is because Windows will run an integrity check when installing a new app. This is Authenticode technology, for any software run via Windows.
  2. However, because we are under the context of a VSTO, and because Microsoft Office verifies the integrity of COM Add-Ins each time they are called, you also need to sign your project DLL via the Manifest Generation and Editing Tool. This is Mage technology, specific for deployment manifests such as theses relied upon by ClickOnce.
  3. Because we are under the context of a ClickOnce deployment, you also need to sign the deployment manifest, which guarantees the link to the remote location which contains the installation files is legit. This is Mage technology.
  4. And Finally, ClickOnce also requires to sign the application manifest; that is, the listing of all the files included in the release (setup.exe / main DLL, and others requisites such as supporting DLLs). This is Mage technology.

Worth noting

In the past, in terms of security Authenticode stepped ahead faster than Mage: Authenticode required to sign SHA256 digests, whilst Mage only supported SHA1 digests. Hence the requirement to sometimes sign the same file twice. See full topic here.

This however, seems to be a problem of the past.


How to proceed

I am using an EV code signing dongle provided by Sectigo. All I have to do to sign and publish the solution via ClickOnce is:

  1. Run SafeNet Authentication Client Tools
  2. Plug the dongle and make sure it appears in the SafeNet client
  3. In Visual Studio (VS 2017 here), go to Project / Properties / Signing and choose [Select from Store...]
  4. Publish the solution (Publish Tab, click [Publish Now])
  5. SafeNet will ask you for the Signing Certificate password. Note sometime you may have to type your password twice, not sure why.
  6. The Solution is fully published and all relevant documents mentioned above are signed.
Related