VirtualBox

Changes between Initial Version and Version 1 of Ticket #20226, comment 16


Ignore:
Timestamp:
Mar 1, 2021 1:55:43 PM (3 years ago)
Author:
fth0

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #20226, comment 16

    initial v1  
    55The VBoxRT.dll files from VirtualBox 6.1.18r142142, 6.1.19r142777 and 6.1.19.r142917 all use the same expired Microsoft cross-certificate. The major difference is the point in time when the code signature was created. Therefore, I would expect that a rebuild of 6.1.18 today or a new build of 6.1.20 would also be rejected by the VirtualBox hardening code. What am I missing?
    66
    7 Was attestation signing already used when building the 6.1.18 release, or will it be only used starting with the next official release? If it is the former, why would the VirtualBox hardening code not reach the check of the expired cross-certificate and reject VBoxRT.dll?
     7Was attestation signing already used when building the 6.1.18 release, or will it be only used starting with the next official release? If it was the former, why would the VirtualBox hardening code on a new release build today not reach the check of the expired cross-certificate and reject VBoxRT.dll?

© 2023 Oracle
ContactPrivacy policyTerms of Use