How to sign user space binary with force integrity check (deprecated MSFT cross-signing)

Viewed 43

We used to have a binary running in user space built with VC++ /integritycheck flag which sets IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY flag on executable (see more here and here). We signed it with our old certificate and it run smoothly. Now we were given new certificate and binary is blocked by security check (defender prompt + log in event log).

Audit fail event

  • Yes, we added certificate to our trusted store.
  • Yes, we used page hash (/ph) switch while signing.
  • New cert running fine if we enable test sign on a platform (through bcdedit)

The major difference seems to be that new certificate is not cross signed by Microsoft. Cross signing is no longer supported so maybe anyone knows if there's alternative or how to workaround it? Maybe /integritycheck flag for user space code is no longer valid?

Same issue we found at MSFT forum https://docs.microsoft.com/en-us/answers/questions/348812/signed-file-fails-to-start-because-of-bad-signatur.html. Still no precise answers how to solve it.

0 Answers
Related