<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Getting started with code signing for under $100</title>
	<atom:link href="http://www.jeff.wilcox.name/2010/02/codesigning101/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jeff.wilcox.name/2010/02/codesigning101/</link>
	<description>Silverlight, rich client apps and web development</description>
	<lastBuildDate>Mon, 06 Feb 2012 19:09:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Ciank</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-7766</link>
		<dc:creator>Ciank</dc:creator>
		<pubDate>Thu, 30 Jun 2011 11:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-7766</guid>
		<description>Can you use the same cert to sign Adobe Air and Java Jar files?
</description>
		<content:encoded><![CDATA[<p>Can you use the same cert to sign Adobe Air and Java Jar files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mitchell Vincent</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-7746</link>
		<dc:creator>Mitchell Vincent</dc:creator>
		<pubDate>Mon, 27 Jun 2011 23:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-7746</guid>
		<description>Hi Erik - I&#039;m not sure how it works on others but on my order page (codesigning.ksoftware.net) the keys are generated on your computer using Javascript and the private key never leaves your machine. </description>
		<content:encoded><![CDATA[<p>Hi Erik &#8211; I&#8217;m not sure how it works on others but on my order page (codesigning.ksoftware.net) the keys are generated on your computer using Javascript and the private key never leaves your machine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Creating your First Silverlight Client Application: Twitter and COM, of course - Pete Brown's 10rem.net</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2699</link>
		<dc:creator>Creating your First Silverlight Client Application: Twitter and COM, of course - Pete Brown's 10rem.net</dc:creator>
		<pubDate>Fri, 28 May 2010 23:02:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2699</guid>
		<description>[...] next thing you should do is sign your XAP. We won&#039;t do that here, but there is a great walkthrough on XAP signing for elevated trust apps here. The walkthrough also shows what the various install dialogs look [...]</description>
		<content:encoded><![CDATA[<p>[...] next thing you should do is sign your XAP. We won&#39;t do that here, but there is a great walkthrough on XAP signing for elevated trust apps here. The walkthrough also shows what the various install dialogs look [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin H</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2685</link>
		<dc:creator>Kevin H</dc:creator>
		<pubDate>Tue, 25 May 2010 19:59:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2685</guid>
		<description>Thanks for the great article. It really helped me get through the weeds!

Kevin</description>
		<content:encoded><![CDATA[<p>Thanks for the great article. It really helped me get through the weeds!</p>
<p>Kevin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2393</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sun, 04 Apr 2010 01:31:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2393</guid>
		<description>Excellent job in making this simple and straight forward.

Thank you much</description>
		<content:encoded><![CDATA[<p>Excellent job in making this simple and straight forward.</p>
<p>Thank you much</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Bush</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2373</link>
		<dc:creator>Jim Bush</dc:creator>
		<pubDate>Thu, 01 Apr 2010 18:54:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2373</guid>
		<description>Yeah ksoftware are great.  As described above its much easier than b4 - you used to have to install openssl to convert key files and a whole lot of pain.

Comodo are sticklers for the documentation so make sure you&#039;ve got your ducks in a row first - eg. if you use a POBOX, have your bank statement and utility bill sent there.   Comodo reps do not seem to use any discretion, so even if you have the &#039;right&#039; address in one place and not another, they wont like it.  You can&#039;t &quot;prove&quot; it&#039;s OK, you just have to give them what they want....</description>
		<content:encoded><![CDATA[<p>Yeah ksoftware are great.  As described above its much easier than b4 &#8211; you used to have to install openssl to convert key files and a whole lot of pain.</p>
<p>Comodo are sticklers for the documentation so make sure you&#8217;ve got your ducks in a row first &#8211; eg. if you use a POBOX, have your bank statement and utility bill sent there.   Comodo reps do not seem to use any discretion, so even if you have the &#8216;right&#8217; address in one place and not another, they wont like it.  You can&#8217;t &#8220;prove&#8221; it&#8217;s OK, you just have to give them what they want&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin S.</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2372</link>
		<dc:creator>Kevin S.</dc:creator>
		<pubDate>Thu, 01 Apr 2010 13:52:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2372</guid>
		<description>Wow, Jeff, this is a terrific blog.  I had run across the KSoftware sign while looking for the cheapest CA I could use to sign my jars, but I was leary of them because it sounded too good to be true.

Thanks for all the details about the process, it sounds like a bit of pain but no too bad.

Carl (above) mentioned startssl.com, but didn&#039;t see a CA with that name in my Java cacerts file, so it might not be of value.   Comodo is defiinitely there.</description>
		<content:encoded><![CDATA[<p>Wow, Jeff, this is a terrific blog.  I had run across the KSoftware sign while looking for the cheapest CA I could use to sign my jars, but I was leary of them because it sounded too good to be true.</p>
<p>Thanks for all the details about the process, it sounds like a bit of pain but no too bad.</p>
<p>Carl (above) mentioned startssl.com, but didn&#8217;t see a CA with that name in my Java cacerts file, so it might not be of value.   Comodo is defiinitely there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christophe</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2349</link>
		<dc:creator>Christophe</dc:creator>
		<pubDate>Fri, 26 Mar 2010 19:13:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2349</guid>
		<description>Also bought a certificate, a quick and painless process. Kudos to Comodo and K Software.

@Erik: the private key doesn&#039;t leave your browser. As Rupert said, only the public key is sent to Comodo. That&#039;s why you have to download the signed certificate from the same browser that generated the key.</description>
		<content:encoded><![CDATA[<p>Also bought a certificate, a quick and painless process. Kudos to Comodo and K Software.</p>
<p>@Erik: the private key doesn&#8217;t leave your browser. As Rupert said, only the public key is sent to Comodo. That&#8217;s why you have to download the signed certificate from the same browser that generated the key.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rupert</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2344</link>
		<dc:creator>Rupert</dc:creator>
		<pubDate>Thu, 25 Mar 2010 16:44:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2344</guid>
		<description>Maybe I misunderstood, but AFAIK the issuing company *does not* have your private key. You generate the private key locally and send them only the public part to sign. That&#039;s the reason you have to go back to the same PC to retrieve the certificate: that&#039;s where the private portion is.</description>
		<content:encoded><![CDATA[<p>Maybe I misunderstood, but AFAIK the issuing company *does not* have your private key. You generate the private key locally and send them only the public part to sign. That&#8217;s the reason you have to go back to the same PC to retrieve the certificate: that&#8217;s where the private portion is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A guide to what has changed in the Silverlight 4 RC</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2293</link>
		<dc:creator>A guide to what has changed in the Silverlight 4 RC</dc:creator>
		<pubDate>Mon, 15 Mar 2010 17:44:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2293</guid>
		<description>[...] You can also sign your XAP using self-signed certificates.  If you do so, it is likely that you are not a trusted CA on machines and would have to instruct your users further.  In my opinion, it is better to acquire a trusted CA cert for external applications.  Take a look at Jeff Wilcox’s epic post on Code Signing 101. [...]</description>
		<content:encoded><![CDATA[<p>[...] You can also sign your XAP using self-signed certificates.  If you do so, it is likely that you are not a trusted CA on machines and would have to instruct your users further.  In my opinion, it is better to acquire a trusted CA cert for external applications.  Take a look at Jeff Wilcox’s epic post on Code Signing 101. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Philipp Winterberg</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2289</link>
		<dc:creator>Philipp Winterberg</dc:creator>
		<pubDate>Fri, 12 Mar 2010 23:08:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2289</guid>
		<description>Thanks Jeff! Very helpful! :-)</description>
		<content:encoded><![CDATA[<p>Thanks Jeff! Very helpful! <img src='http://www.jeff.wilcox.name/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mitchell Vincent</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2287</link>
		<dc:creator>Mitchell Vincent</dc:creator>
		<pubDate>Fri, 12 Mar 2010 02:36:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2287</guid>
		<description>Thanks Jeff - an excellent article that covers everything I was sitting down to write tonight.

If anyone has any questions or concerns about ordering through K Software, please email me - support at ksoftware.net

Thanks again Jeff!</description>
		<content:encoded><![CDATA[<p>Thanks Jeff &#8211; an excellent article that covers everything I was sitting down to write tonight.</p>
<p>If anyone has any questions or concerns about ordering through K Software, please email me &#8211; support at ksoftware.net</p>
<p>Thanks again Jeff!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Notsotrusting</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2269</link>
		<dc:creator>Notsotrusting</dc:creator>
		<pubDate>Sun, 07 Mar 2010 23:06:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2269</guid>
		<description>Oh, I forgot to say. Good article, thanks. One of the key points I took away from this was the &quot;trusted publishers&quot; bit. Really, signing is not so complicated. Getting the certificate and keep the keys secure are more of an issues, as is reliable timestamping for when certificates expire (IMO).</description>
		<content:encoded><![CDATA[<p>Oh, I forgot to say. Good article, thanks. One of the key points I took away from this was the &#8220;trusted publishers&#8221; bit. Really, signing is not so complicated. Getting the certificate and keep the keys secure are more of an issues, as is reliable timestamping for when certificates expire (IMO).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Notsotrusting</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2268</link>
		<dc:creator>Notsotrusting</dc:creator>
		<pubDate>Sun, 07 Mar 2010 23:02:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2268</guid>
		<description>Yes, well Jack Bauer may work for them and Jack Bauer may one day get royally pissed off when they sack him and he may take a bagful, or two, of PKs with him to screw the man over.</description>
		<content:encoded><![CDATA[<p>Yes, well Jack Bauer may work for them and Jack Bauer may one day get royally pissed off when they sack him and he may take a bagful, or two, of PKs with him to screw the man over.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Wilcox</title>
		<link>http://www.jeff.wilcox.name/2010/02/codesigning101/comment-page-1/#comment-2261</link>
		<dc:creator>Jeff Wilcox</dc:creator>
		<pubDate>Wed, 03 Mar 2010 16:17:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeff.wilcox.name/2010/02/codesigning101/#comment-2261</guid>
		<description>@Erik,
Not sure I agree with your &quot;Not only do you have to trust that company to never use your key, but you also have to trust them to keep it secret.&quot; statement. We&#039;re talking about some fairly large security firms here, whose job is keeping secrets and the trust of not only their customers, but also the Internet itself.

I doubt anybody at a root CA has any interest in signing anyone&#039;s code - unless it&#039;s all part of some action sequence with Jack Bauer in it.</description>
		<content:encoded><![CDATA[<p>@Erik,<br />
Not sure I agree with your &#8220;Not only do you have to trust that company to never use your key, but you also have to trust them to keep it secret.&#8221; statement. We&#8217;re talking about some fairly large security firms here, whose job is keeping secrets and the trust of not only their customers, but also the Internet itself.</p>
<p>I doubt anybody at a root CA has any interest in signing anyone&#8217;s code &#8211; unless it&#8217;s all part of some action sequence with Jack Bauer in it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

