Good news regarding Windows code signing for QElectroTech!
We have made significant progress in setting up proper Authenticode signing for our Windows MSI packages through the SignPath OSS program.
Here is what has been accomplished:
- Our application to the SignPath OSS program has been accepted
- The GitHub Actions CI/CD pipeline has been fully configured to automatically submit signing requests after each successful Windows build
- The MSI artifact configuration has been set up to sign both the installer package and all nested executables and DLLs
- A first test signing request was successfully processed, with all verifications passing (source code origin, build workflow, malware scan)
We are now waiting for SignPath to activate the production certificate, after which every nightly Windows MSI build will be automatically signed with a trusted certificate.
This means that in the near future, users will no longer see the "Unknown publisher" warning when installing QElectroTech on Windows.
Thanks to everyone who encouraged us to pursue this — it has been a long time coming!
"Le jour où tu découvres le Libre, tu sais que tu ne pourras jamais plus revenir en arrière..."Questions regarding QET belong in this forum and will NOT be answered via PM! – Les questions concernant QET doivent être posées sur ce forum et ne seront pas traitées par MP !