Search

Allow other Certificates in WinQual (not only Verisign) by Stefan 000000

Active

79
0
Sign in
to vote
Type: Suggestion
ID: 531903
Opened: 2/8/2010 4:33:15 AM
Access Restriction: Public
0
Workaround(s)
The need to use a VeriSign Certificate blocks me and many other developers to join WinQual.
Details (expand)
Detail:
Even Thawte is not allowed (which belongs to VeriSign). I don't think there are any reasons that certs of other authorities cannot be used.
File Attachments
0 attachments
Sign in to post a comment.
Posted by NQI on 1/10/2011 at 11:55 AM
VERY suspicious. The double talking answers I've seen out there for why winqual does not accept any other CA except VeriSign is a real let down. Give your head a shake, my company has paid for VB6, VS2005, VS2010, Server and a Windows (and office) licence for every user in the company. Then you tell me that I have to go and pay an inflated fee to a specific CA and that I cannot shop around for a CA that I want. Smells of kickbacks or someother nefarious relationship. There's some saying out there about a last straw that comes to mind.
Posted by Applied Maths NV on 10/14/2010 at 1:59 AM
Well I just purchased a brand new “Code Signing (Class 3) Digital ID” from VeriSign specifically for Winqual (we normally use Comodo certificates), and we still receive the following error while uploading the signed Winqual.exe file:
"The Winqual.exe file you uploaded is signed with an invalid digital certificate."

It really does not make any sense not to trust other root certificates like Comodo for Winqual, and really smells like protectionism. I’m sure that if VeriSign had a more neutral relationship with Microsoft this requirement would never have been imposed. This really is a great example of unhealthy mixed interests, and this could be a real treat for an institution like the European commission, if they would care to set their teeth into this. Maybe Microsoft will eventually come-up with Winqual N or K editions?

God only knows why the Microsoft legal department is still not sensitive to these kind of issues.
Posted by WolfgangP on 8/23/2010 at 7:55 AM
For an Austrian StartUp it is cumbersome to impossible to get a certificate from VeriSign. VeriSign is not able to accept the proof of identity which are used here (excerpt of commercial register).

Winqual does not trust CAs whose Rootcertificate is contained in the Windows Rootcertificate Store since 2003.
This kind of protectionism feels totally strange to me.

Please change that asap !!!
Posted by coredeveloper on 5/31/2010 at 5:59 AM
I think the problem could be solved after another antimonopoly Claim or else. Microsoft won’t do anything without kick in the...
Posted by Jon456 on 5/11/2010 at 2:26 PM
There is a fairly large community facing this limitation.

Here is one set of users:
http://stackoverflow.com/questions/611472/winqual-why-would-wer-not-accept-code-signing-certificates

Please remove this limitation so that software and drivers which really DO pass all of your tests can be said to pass Windows logo testing.
Posted by lakecomm on 3/31/2010 at 9:41 AM
Microsoft - your almost there. Thanks for dropping the Windows 7 logo certification fees but PLEASE allow us to sign our code with a certificate from any valid root CA. Verisign certificates (after the first year discount) are a huge rip-off. Thanks.
Posted by Djs_Djs on 3/26/2010 at 5:51 AM
This is very curious and frustrating. Obviously for Windows 7 the logo program has undergone massive changes to make it more accessible to smaller software developers, yet this one relic stands in the way of broad adoption of the program. Not only does it not make sense from a product management standpoint, but it is frequently discovered in a very frustrating way - after already investing the time and money in another, more reasonably priced certificate - making the sting of the higher price even more off putting.
Posted by Andrew6666 on 3/7/2010 at 6:41 AM
And what's worse, the Windows 7 Client Software Logo Toolkit accepts other (non-Verisign) code signing certs as a PASS --- as does Windows Vista/7 UAC --- and nowhere in the documentation does it say "but you won't be able to submit these results without a Verisign cert". This is quite unbelievable.

--Andrew
Posted by MCCZ on 2/26/2010 at 12:31 PM
I am also quite irritated that Microsoft artificially creates monopoly and clearly pushes other companies of the running.

Personally, I would really like to have my software certified, but I am not able to get certificate from Verisign, even I have a valid code signing certificate from Thawte, which is generally also considered as a trusted authority. As a result, I am out of the game just for this foolish limitation.
Posted by Microsoft on 2/11/2010 at 6:41 AM
Hello,

Thank you for your feedback.

We are aware of it and it may be incorporated in future programs.

Best Regards
Windows 7 Software Logo Team
Posted by BillVo on 2/9/2010 at 1:17 PM
Clearly, Microsoft can offer no reason why its Winqual team should not endure the inconvenience of adding additional "Trusted Root Certificate Authorities" to its authentication system. The most common vendors providing certs for Microsoft Authenticode should be supported: Thawte, Comodo, etc.

By ignoring this issue, the Winqual team seems to suggest that the quality of Windows applications is less important than protecting the revenue of a certificate authority that just *might* be over-priced.

see also: http://stackoverflow.com/questions/611472/winqual-why-would-wer-not-accept-code-signing-certificates
Sign in to post a workaround.