Pale Moon 27.4.2 x86 installer - no digital signature

Users and developers helping users with generic and technical Pale Moon issues on all operating systems.

Moderator: trava90

Forum rules
This board is for technical/general usage questions and troubleshooting for the Pale Moon browser only.
Technical issues and questions not related to the Pale Moon browser should be posted in other boards!
Please keep off-topic and general discussion out of this board, thank you!
Freezing Moon

Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Freezing Moon » 2017-08-22, 12:22

As the title says.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-08-22, 12:34

"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Freezing Moon

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Freezing Moon » 2017-08-22, 12:55


User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-08-22, 12:59

Aha, Okay. They aren't code-signed.
That was indeed a slip-up on my part -- if you want to verify the integrity, check the SHA posted on the website or use the PGP signatures, please.

I'll code-sign them and update later today.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

dark_moon

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by dark_moon » 2017-08-22, 13:01

Same for x64 version.

GPG sig and SHA2-256 checksum is fine.

Freezing Moon

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Freezing Moon » 2017-08-22, 13:24

Avast blocked installer (Cyber Capture) and sent the file to Avast Virus Lab.
Of course it is a FP.This is because of lack of digital signature.

This file can be dangerous :

http://imgur.com/a/HONqc

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-08-22, 13:35

Yeah hold yer horses! I'm working on it, damnit.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-08-22, 13:46

Updated the installers with code-signed versions.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Freezing Moon

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Freezing Moon » 2017-08-22, 13:58

Thanks. Everything is fine now.
Cyber Capture was activated again. This time it was for setup.exe from Temp folder during installation, but I clicked on
'Run it anyway' or something like that.

Freezing Moon

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Freezing Moon » 2017-11-15, 10:38

Same thing with 27.6.1 x64 installer.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-11-15, 13:26

Freezing Moon wrote:Same thing with 27.6.1 x64 installer.
Fixed. Sorry about that. 's what happens when you're chronically short on sleep leading up to a release.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-11-15, 13:39

As an aside, since StartCom has fallen out of grace by people, I'm not sure if I'll be able to get a new code signing certificate when the current one expires in January.
Does anyone know of affordable options for a FOSS project like ours?
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

JustOff

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by JustOff » 2017-11-15, 14:46

I don't know any cheaper options from trusted authorities than $85/year form Comodo. Centrum used to be free for OSS, now they offer €86/1st year + €28/renewal, but it looks somehow questionable.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-11-16, 09:49

I've been in contact with Comodo and after payment it boiled down to them not actually doing IV certificates and requiring a registered business. Any alternative that condenses down to the actual CA being Comodo won't work.

Maybe StartCOM will still work for code signing; after all, it's still a valid CA, just not trusted for "the web" because of arbitrary politics. I'll have to do some research.

EDIT: asked StartCOM, and no, they've been distrusted on all platforms, meaning code signing is also out.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35636
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Pale Moon 27.4.2 x86 installer - no digital signature

Unread post by Moonchild » 2017-11-16, 10:34

I guess Certum is the only option. Now to wait for Comodo's refund so I can pay for it :P
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite