We have ActiveX components (OCXs/DLLs) and .NET components (DLLs) used by our customers to build end-user apps for the Windows platform. All these components are digitally signed before they reach the customer's computer.
One of our customers asked us not to sign our components because this can cause significant delays (up to 2 minutes) when an app with our component starts. One of the possible reason: a server used to check the digital sign is inaccessible for some reasons. This was the case not only for our components, but for components from other vendors too.
My questions:
Why such a delay may occur?
Is it ok not to sign binary components?