Re: Driver status digitally unsigned

Tech-Archive recommends: Speed Up your PC by fixing your registry



On 17 Apr 2006 22:29:30 -0700, sriivii@xxxxxxxxxxx wrote:

Hello,

I have been using Verisign codesigning certificate to
digitally sign my catalog file (which digitally sign my driver file). I
was able to create a catalog file with "MakeCat" utility, was able to
sign the catalog file with "SignCode" and was able to verify the
catalog file's validity using "ChkTrust" tool.

But, after installing the driver, the driver's digital
signature property in the "Device Manager" still displays it to be
digitally unsigned.

When I tried analysing the setupapi.log, I noticed the
following statement:

" 0x800B0109 : A certificate chain processed, but terminated in a root
certificate which is not trusted by the trust provider. "

Note - When I try verifying the same catalog file using "Signtool", I
get the following error:

"SignTool Error: WinVerifyTrust returned error: 0x800B0110
The certificate is not valid for the requested usage."

Any clue ?


You are self signing your driver and that is only supported on
specific OS releases for specific classes of drivers and also requires
installation of certificates on the target system or access from the
target system to a certificate server in the domain.

Do some research on self signed drivers.


Thanks,
Srivi.


=====================
Mark Roddy DDK MVP
Windows Vista/2003/XP/2000 Consulting
Device and Filesystem Drivers
Hollis Technology Solutions 603-321-1032
www.hollistech.com
.



Relevant Pages

  • self-signed NIC coinstaller prevent the nic from being disabled?
    ... We have a self-signed NIC miniport driver package ... which includes the driver, coinstaller, inf and catalog file. ... the commercial CA certificate for the sign self, ... The problem is after driver and coinstaller are installed on Windows 2003, ...
    (microsoft.public.development.device.drivers)
  • Re: Driver Signing Requirement for Windows,...
    ... enough of a software developer, I should have a certificate, and I ... I don't care whether a consultant wrote it - ... The OS's that require driver certification are top of the line, ... signing at best delays products to market and at ...
    (microsoft.public.development.device.drivers)
  • Digital sign a driver for XP and Vista
    ... My company has just bought a Class 3 certificate from Verisign to digitally sign some drivers. ... The driver is made up by a .inf file, a .sys file and a .dll file. ... SHA1 hash: 8FBE4D070EF8AB1BCCAF2A9D5CCAE7282A2C66B3 ...
    (microsoft.public.development.device.drivers)
  • Re: newbie@KMDF: can not build a signed catalog file for Vista 64.
    ... I now have to port a driver to WDF/KMDF and try to get familiar with the ... This is how I build ECHO: ... Now I create an catalog file, ... Issued to: Thawte Timestamping CA ...
    (microsoft.public.development.device.drivers)
  • RE: Driver signing failure on Vista 64
    ... at Equifax, i.e. it does not have the Microsoft Root Certificate Authority at ... I am working on a tool that includes a filter driver in the storage stack. ... Intel Code Signing External Cert for IPEAK External Cert ...
    (microsoft.public.development.device.drivers)