N
N
Nikolay19732018-05-17 10:53:36
Antivirus
Nikolay1973, 2018-05-17 10:53:36

Why can't I spin up the Comodo certificate in SmartScreen?

I bought a Comodo Code Signing certificate (not an EV certificate) for an individual to sign software in January 2018. I bought it through EmaroSSL, a certificate for 1 year.
Actually, the certificate was purchased in order to remove SmartScreen when users download the program and minimize false positives from antiviruses.
Regarding SmartScreen - the situation has not changed - when the user downloads the program, the SmartScreen warning screen appears all the time. I know that in order to remove this window, the certificate must gain reputation. At one time I bought a SrartSSL certificate, there were no problems with this - the reputation was gained in about 30 days, and after that any applications signed with a certificate that had already gained a reputation were downloaded without SmartScreen.
What we have now - despite the fact that the certificate was purchased in January, the software from the site was downloaded from SmartScreen for about 2.5 months. After that, SmartScreen stopped appearing - but it seems that it was not the certificate that gained the reputation, but the specific distribution kit of the program using a specific link.
If something else (new versions of the program) is signed with this certificate and put on the site, the problem remains - SmartScreen appears when downloading these programs from the site. The number of distributions signed with the certificate and handed over to customers is already several times greater than the number signed in 2015 - but the certificate has not yet been rolled out.
It turns out that such a certificate is, in principle, a useless thing - after all, even a regular distribution kit that is not signed by any certificate at all is gaining reputation in SmartScreen in the same way.
What to do in this situation - how to remove SmartScreen when downloading programs signed with a Comodo certificate?

Answer the question

In order to leave comments, you need to log in

2 answer(s)
N
Nikolay1973, 2018-07-24
@Nikolay1973

Finally unraveled. Six months have passed. Apparently, Microsoft's requirements for the number of downloads since then (after 2015) have increased 10 times.

V
Vladislav Kuvarin, 2020-07-03
@Modaje

Nikolai, indeed Microsoft's logic is a little unclear. Why purchase a certificate from a trusted certification authority in order to sign your software, subject to pop-up notifications of distrust for this software.
One solution is to give a certificate for more than 1 year. Thus, you can kill two birds with one stone -
1. The trust of the certificate added to the Smartscreen white list will increase. Since the renewal is still a new certificate, which will also need to regain the reputation of good software.
2. If the goal is not only signing, but also to overcome notifications about "untrusted publisher" instantly, then an EV (Extended Validation) certificate is needed, which is also issued for IP, if taken from GlobalSign.
I would like to note that when you sign with an OV certificate, you protect your software from any changes. Also about an unsigned distribution that gains reputation over time - given that when updating the software version, you will need to re-gain reputation for the new version, which is probably not very convenient and it will be easier to purchase a certificate from a trusted certification authority.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question