Time Stamping Server
In order to sign your code and documents, you pass the code and documents which you want to authenticate through a hashing algorithm and then use your private key to sign the hash, which results in a digital signature. You then build a signature block, which contains the digital signature and the code-signing certificate.
Tools like Microsoft's SignTool let you time stamp the signature block based on the current date and time that a time stamping service provider, such as Sectigo, provides. Finally, you bind the time stamped signature block to the original software. Now you can publish the signed software on your Web site for download.
As part of this process you will need to know the URL of Sectigo's time stamping server:
There are two popular time stamping protocols, which are both supported by our time stamping server:
- RFC 3161 time stamping is used by SignTool (using the "/tr" parameter) and other applications (such as jarsigner). Our time stamping server automatically selects the appropriate signature algorithm (RSA/SHA-1, RSA/SHA-256 or RSA/SHA-384) with which to sign each timestamp, based on the hash algorithm you specify (e.g. via SignTool's "/td" parameter).
- Authenticode time stamping is used by older versions of SignTool (using the "/t" parameter) and SignCode. Due to the design of this protocol, it is not possible for our time stamping server to automatically select the appropriate signature algorithm. We currently use RSA/SHA-1 by default, for compatibility with Windows Vista and XP. However, you may request a different signature algorithm by appending "?td=<hash_algorithm>" to the URL. e.g. http://timestamp.comodoca.com?td=sha256.
Note: If you are signing several pieces of software with a script, please add a delay of 15 seconds or more between signings so that you're not hammering our servers.