N
N
Nikolai20152015-03-12 02:33:20
Antivirus
Nikolai2015, 2015-03-12 02:33:20

What Code Signing certificate do I need to get to sign code?

I am a shareware developer.
Due to the fact that my program has a lot of false positives (there used to be 5 positives on VirusTotal, now there are 20), I want to get a Code Signing certificate for an individual.
The certificate should also remove the scary SmartScreen message when downloading and running software from the site by users "Windows protected your PC" (which, I think, loses at least 50% of new potential customers).
Question - what Code Signing certificate to receive?
Is it better to get StartSSL or Comodo? There is a difference? Why is one of them $60 and the other $100?
And if you order a certificate through the site https://www.emaro-ssl.ru- generally it turns out 8000 rubles (which is even more than 100 dollars) - what are the advantages before ordering a certificate directly from Comodo? And if you get it directly through this service, will it be possible to renew it directly from Komodo or now you have to pay 8000 every year?
The question is, what is the difference - and for what exactly does it make sense to pay more?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
V
Vladimir Martyanov, 2015-03-12
@vilgeforce

The signature will not get rid of "false" positives. Surely you have some kind of advertising rubbish in your software.

I
IRabinovich, 2015-03-19
@IRabinovich

I use StartSSL, the flight is normal. The question is whether there is a root certificate in the Windows store, Comodo has more of them for older OS versions and service packs, which has long been uncritical. The verification process in StartSSL is more adequate, by the way, than in Komodo, my last home phone was mistaken for a mobile phone and they demanded to provide a home phone, after which I demanded a refund. :)

N
Nikolai2015, 2015-04-21
@Nikolai2015

Received a Code Signing - StartSSL certificate for $60. I had to wait for a letter by mail for 19 days - finally, I waited.
I figured out how to create a pfx file and how to sign a program with it (and not just sign it, but even using a timestamp).
But SmartScreen still does not allow users to download the program - the same message appears "The program has protected your computer."
Although, for the sake of justice, now if the user clicks "Read more" and then agrees - now the second message comes out already normal - instead of "Allow to run a program from an unknown publisher" now "Publisher: xxx - allow launch?"
But how do you get rid of the "Windows has protected your computer" message? It turns out,

V
Vladislav Kuvarin, 2020-07-03
@Modaje

A Comodo (Sectigo) certificate for an individual can also be obtained at a price of 5,992 rubles per year when purchasing a certificate for a longer validity period. We have issued dozens of certificates to individual developers in emaro-ssl, we work on a postpaid basis, so you can pay the cost of the certificate when it is actually received and tested. Regarding certification, you can and will contact the appropriate office yourself (unfortunately, this is a requirement on the part of the certification authority)
https://support.sectigo.com/Com_KnowledgeDetailPag...

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question