Skip to content
This repository has been archived by the owner on Feb 23, 2021. It is now read-only.

Failed to auto-update to 0.5.7 due to certificate error #1313

Open
andronoob opened this issue Sep 28, 2019 · 8 comments
Open

Failed to auto-update to 0.5.7 due to certificate error #1313

andronoob opened this issue Sep 28, 2019 · 8 comments

Comments

@andronoob
Copy link

Description

I'm running LNApp 0.5.6 win32 on Windows 10, it failed to auto-update to 0.5.7.

Screenshot and/or logs if applicable

Sign verification failed, installer signed with incorrect certificate: publisherNames: Sectigo RSA Code Signing CA, raw info: {
  "SignerCertificate": {
    "FriendlyName": "",
    "IssuerName": {
      "Name": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "NotAfter": "/Date(1597449599000)/",
    "NotBefore": "/Date(1565827200000)/",
    "PrivateKey": null,
    "PublicKey": {
      "Key": "System.Security.Cryptography.RSACryptoServiceProvider",
      "Oid": "System.Security.Cryptography.Oid",
      "EncodedKeyValue": "System.Security.Cryptography.AsnEncodedData",
      "EncodedParameters": "System.Security.Cryptography.AsnEncodedData"
    },
    "SerialNumber": "00DF494F2254FDE8FF535FD3CBC32755E8",
    "SignatureAlgorithm": {
      "Value": "1.2.840.113549.1.1.11",
      "FriendlyName": "sha256RSA"
    },
    "Thumbprint": "2221C28264ABFA0E03E477DD020B10C0B65F053E",
    "Version": 3,
    "Issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB",
    "Subject": "CN=\"LIGHTNING LABS, INC.\", O=\"LIGHTNING LABS, INC.\", STREET=720 University Ave Suite 200, L=Palo Alto, S=California, PostalCode=94301, C=US"
  },
  "TimeStamperCertificate": {
    "Archived": false,
    "Extensions": [
      "System.Security.Cryptography.X509Certificates.X509BasicConstraintsExtension",
      "System.Security.Cryptography.X509Certificates.X509EnhancedKeyUsageExtension",
      "System.Security.Cryptography.X509Certificates.X509KeyUsageExtension",
      "System.Security.Cryptography.X509Certificates.X509Extension",
      "System.Security.Cryptography.X509Certificates.X509Extension",
      "System.Security.Cryptography.X509Certificates.X509Extension",
      "System.Security.Cryptography.X509Certificates.X509SubjectKeyIdentifierExtension",
      "System.Security.Cryptography.X509Certificates.X509Extension"
    ],
    "FriendlyName": "",
    "IssuerName": {
      "Name": "CN=Symantec Time Stamping Services CA - G2, O=Symantec Corporation, C=US",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "NotAfter": "/Date(1609286399000)/",
    "NotBefore": "/Date(1350518400000)/",
    "HasPrivateKey": false,
    "PrivateKey": null,
    "PublicKey": {
      "Key": "System.Security.Cryptography.RSACryptoServiceProvider",
      "Oid": "System.Security.Cryptography.Oid",
      "EncodedKeyValue": "System.Security.Cryptography.AsnEncodedData",
      "EncodedParameters": "System.Security.Cryptography.AsnEncodedData"
    },
    "SerialNumber": "0ECFF438C8FEBF356E04D86A981B1A50",
    "SubjectName": {
      "Name": "CN=Symantec Time Stamping Services Signer - G4, O=Symantec Corporation, C=US",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "SignatureAlgorithm": {
      "Value": "1.2.840.113549.1.1.5",
      "FriendlyName": "sha1RSA"
    },
    "Thumbprint": "65439929B67973EB192D6FF243E6767ADF0834E4",
    "Version": 3,
    "Handle": 2287546697632,
    "Issuer": "CN=Symantec Time Stamping Services CA - G2, O=Symantec Corporation, C=US",
    "Subject": "CN=Symantec Time Stamping Services Signer - G4, O=Symantec Corporation, C=US"
  },
  "Status": 0,
  "StatusMessage": "签锟斤拷锟斤拷通锟斤拷锟斤拷证锟斤拷"
}
Error: Error: New version 0.5.7-alpha is not signed by the application owner: publisherNames: Sectigo RSA Code Signing CA, raw info: {
  "SignerCertificate": {
    "FriendlyName": "",
    "IssuerName": {
      "Name": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "NotAfter": "/Date(1597449599000)/",
    "NotBefore": "/Date(1565827200000)/",
    "PrivateKey": null,
    "PublicKey": {
      "Key": "System.Security.Cryptography.RSACryptoServiceProvider",
      "Oid": "System.Security.Cryptography.Oid",
      "EncodedKeyValue": "System.Security.Cryptography.AsnEncodedData",
      "EncodedParameters": "System.Security.Cryptography.AsnEncodedData"
    },
    "SerialNumber": "00DF494F2254FDE8FF535FD3CBC32755E8",
    "SignatureAlgorithm": {
      "Value": "1.2.840.113549.1.1.11",
      "FriendlyName": "sha256RSA"
    },
    "Thumbprint": "2221C28264ABFA0E03E477DD020B10C0B65F053E",
    "Version": 3,
    "Issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=Greater Manchester, C=GB",
    "Subject": "CN=\"LIGHTNING LABS, INC.\", O=\"LIGHTNING LABS, INC.\", STREET=720 University Ave Suite 200, L=Palo Alto, S=California, PostalCode=94301, C=US"
  },
  "TimeStamperCertificate": {
    "Archived": false,
    "Extensions": [
      "System.Security.Cryptography.X509Certificates.X509BasicConstraintsExtension",
      "System.Security.Cryptography.X509Certificates.X509EnhancedKeyUsageExtension",
      "System.Security.Cryptography.X509Certificates.X509KeyUsageExtension",
      "System.Security.Cryptography.X509Certificates.X509Extension",
      "System.Security.Cryptography.X509Certificates.X509Extension",
      "System.Security.Cryptography.X509Certificates.X509Extension",
      "System.Security.Cryptography.X509Certificates.X509SubjectKeyIdentifierExtension",
      "System.Security.Cryptography.X509Certificates.X509Extension"
    ],
    "FriendlyName": "",
    "IssuerName": {
      "Name": "CN=Symantec Time Stamping Services CA - G2, O=Symantec Corporation, C=US",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "NotAfter": "/Date(1609286399000)/",
    "NotBefore": "/Date(1350518400000)/",
    "HasPrivateKey": false,
    "PrivateKey": null,
    "PublicKey": {
      "Key": "System.Security.Cryptography.RSACryptoServiceProvider",
      "Oid": "System.Security.Cryptography.Oid",
      "EncodedKeyValue": "System.Security.Cryptography.AsnEncodedData",
      "EncodedParameters": "System.Security.Cryptography.AsnEncodedData"
    },
    "SerialNumber": "0ECFF438C8FEBF356E04D86A981B1A50",
    "SubjectName": {
      "Name": "CN=Symantec Time Stamping Services Signer - G4, O=Symantec Corporation, C=US",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "SignatureAlgorithm": {
      "Value": "1.2.840.113549.1.1.5",
      "FriendlyName": "sha1RSA"
    },
    "Thumbprint": "65439929B67973EB192D6FF243E6767ADF0834E4",
    "Version": 3,
    "Handle": 2287546697632,
    "Issuer": "CN=Symantec Time Stamping Services CA - G2, O=Symantec Corporation, C=US",
    "Subject": "CN=Symantec Time Stamping Services Signer - G4, O=Symantec Corporation, C=US"
  },
  "Status": 0,
  "StatusMessage": "签锟斤拷锟斤拷通锟斤拷锟斤拷证锟斤拷"
}
@andronoob andronoob changed the title Failed to update to 0.5.7 due to certificate error Failed to auto-update to 0.5.7 due to certificate error Sep 28, 2019
@Roasbeef
Copy link
Member

Where'd you obtain that fragment above from?

@andronoob
Copy link
Author

@Roasbeef I'm running Lightning.exe from windows command prompt console.

@Roasbeef
Copy link
Member

Roasbeef commented Oct 23, 2019 via email

@andronoob
Copy link
Author

andronoob commented Oct 23, 2019

@Roasbeef No. Same problem.

I haven't tried manual update yet, though it should work.

@andronoob
Copy link
Author

andronoob commented Oct 23, 2019

I have manually checked the signature of temp-Lightning-win32v0.5.8-alpha.exe in file property window (with a filesystem permission trick to prevent auto-deletion), it reported that “this digital signature is OK”.

@githorray
Copy link

Still failing to auto-update to 0.5.8. I had to manually install to get on 0.5.7 from 0.5.6.

Error: Error: New version 0.5.8-alpha is not signed by the application owner: pu
blisherNames: Sectigo RSA Code Signing CA, raw info: {
  "SignerCertificate": {
    "FriendlyName": "",
    "IssuerName": {
      "Name": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=G
reater Manchester, C=GB",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "NotAfter": "/Date(1597449599000)/",
    "NotBefore": "/Date(1565827200000)/",
    "PrivateKey": null,
    "PublicKey": {
      "Key": "System.Security.Cryptography.RSACryptoServiceProvider",
      "Oid": "System.Security.Cryptography.Oid",
      "EncodedKeyValue": "System.Security.Cryptography.AsnEncodedData",
      "EncodedParameters": "System.Security.Cryptography.AsnEncodedData"
    },
    "SerialNumber": "00DF494F2254FDE8FF535FD3CBC32755E8",
    "SignatureAlgorithm": {
      "Value": "1.2.840.113549.1.1.11",
      "FriendlyName": "sha256RSA"
    },
    "Thumbprint": "2221C28264ABFA0E03E477DD020B10C0B65F053E",
    "Version": 3,
    "Issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=G
reater Manchester, C=GB",
    "Subject": "CN=\"LIGHTNING LABS, INC.\", O=\"LIGHTNING LABS, INC.\", STREET=
720 University Ave Suite 200, L=Palo Alto, S=California, PostalCode=94301, C=US"

  },

@githorray
Copy link

@githorray
Copy link

Manually updated to 0.5.8. Same error on auto-update to 0.5.9. Maybe still waiting on something to refresh?

Error: Error: New version 0.5.9-alpha is not signed by the application owner: pu
blisherNames: Sectigo RSA Code Signing CA, raw info: {
  "SignerCertificate": {
    "FriendlyName": "",
    "IssuerName": {
      "Name": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=G
reater Manchester, C=GB",
      "Oid": "System.Security.Cryptography.Oid"
    },
    "NotAfter": "/Date(1597449599000)/",
    "NotBefore": "/Date(1565827200000)/",
    "PrivateKey": null,
    "PublicKey": {
      "Key": "System.Security.Cryptography.RSACryptoServiceProvider",
      "Oid": "System.Security.Cryptography.Oid",
      "EncodedKeyValue": "System.Security.Cryptography.AsnEncodedData",
      "EncodedParameters": "System.Security.Cryptography.AsnEncodedData"
    },
    "SerialNumber": "00DF494F2254FDE8FF535FD3CBC32755E8",
    "SignatureAlgorithm": {
      "Value": "1.2.840.113549.1.1.11",
      "FriendlyName": "sha256RSA"
    },
    "Thumbprint": "2221C28264ABFA0E03E477DD020B10C0B65F053E",
    "Version": 3,
    "Issuer": "CN=Sectigo RSA Code Signing CA, O=Sectigo Limited, L=Salford, S=G
reater Manchester, C=GB",
    "Subject": "CN=\"LIGHTNING LABS, INC.\", O=\"LIGHTNING LABS, INC.\", STREET=
720 University Ave Suite 200, L=Palo Alto, S=California, PostalCode=94301, C=US"

  },

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants