Help get this topic noticed by sharing it on Twitter, Facebook, or email.

Code signing certificate not taken effect

Hi

I've installed a code signing certificate from Comodo as per the instructions, I uploaded the .pfx file a day ago, but when I install my extension it still says the author is not verified. Would you be able to take a look?

The id is 19428

Regards
1 person has
this problem
+1
Reply
  • Shlomo (Official Rep) June 13, 2013 12:05
    Hello Matthew,

    I installed the extension on Win7/IE9, Win7/IE10, & Win8/IE10 using URL http://crossrider.com/download/19428 and in each case it installed without any IE warnings stating that the extension author is not verified. Also, checking the EXE file indicates that the extension author is verified (see image).

    Are you still experiencing this problem? If so, which URL are you installing from? Which OS and IE version?

  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned

  • Hi Shlomo,

    Firefox is the main problem, I'm not sure about Chrome yet as I know that's a bit different with the inline install option.

    Also is there anything we can do about how the Icon displays in the Windows install screens? can I specify a different Image for that?
    I obvioudly have to use a transparent png for it to work with Safari but it renders really poorly on the IE install screens.

    Regards
    Matt
  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned

  • Shlomo (Official Rep) June 16, 2013 08:34
    Hello Matthew,

    Code Signing Certificate:
    The Code Signing Certificate is only for the installer (IE, or Chrome & Firefox if they are bundled). It does not apply to Chrome .crx or Firefox .xpi file.

    In General, you can upload your extension to the Chrome Web Store for seamless installation using our (Settings >) Export to Chrome Web Store feature.

    Firefox .xpis can only be loaded via the browser in the usual manner. We are working with the Mozilla review team to authorize the Crossrider framework as a whole and hence provide an Export to AMO feature in line with the Chrome feature. However, even this was already approved by them in the past, due to personnel change on their review team they have restarted the review process of Crossrider. It's a time consuming process so please bear with us until it has been finalized. We will update the entire community when we achieved a breakthrough with AMO and this feature is available.

    Installer Icon:
    Currently, the installer takes the image from the extension's icon and cannot be changed. However, we are constantly working on improvements, so I have forwarded your suggestion on to our development team, who will consider it for future releases.

    In the meantime, you can work around the problem by applying the image you require for the installer to the extension, downloading the extension, and then uploading the Safari version of the icon. Then you can host the installer that has the image you require on your servers.
  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned

  • Thanks Shlomo,

    I'll give that a try with the Icon.

    I'm a bit confused about the code signing, I do admit I've not much experience but on the Comodo product page it says Mozilla is covered, does that mean there's a problem with the certificate they have provided?

    Regards
  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned

  • Can we code-sign our Firefox .xpi file ourselves, or do we need to wait until Crossrider is approved as a whole by the Mozilla review team?
  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned

  • Shlomo (Official Rep) August 03, 2013 18:57
    Hello Bryan,

    Currently, I'm afraid XPI files cannot be signed until the Mozilla Review Team has approved Crossrider.
  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned

  • I got Comodo Code Signing Certificate at just $70/yr from, http://bit.ly/cheap-comodo-code-signi... , isn't it the cheapest one i got??
  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned

  • Where does one start describing the experience of buying a code signing certificate from Comodo? I would say that it is like pulling teeth from a dragon.
    40 days it took from the day of payment to the day it was grudgingly sent to me. This is after 33 emails (16 me to them, 17 them to me), yes 33 !
    To list the main specific complaints:
    1. I chose Comodo because they were the cheapest. Nowhere do they say that you are going to have to spend far more money than the purchase price, and the purchase price is just a beginning. This is DISHONEST in the extreme and I would say FRAUDULENT. The purchase cost me $71, and ended up costing a total of $321 !

    2. After the purchase they give out links to download the quite complicated forms. These involve getting a notary to certify copies of passport, bank and utility documents and to certify that you are you – fair enough, they have to be proper copies. In Australia the police are licenced for the notarization of certified copies, and that’s who I got to do it. You then have to fax Comodo a copy, and then mail them the copy. Apparently they do not understand that every one used email these days!

    3. After chasing them up a 2 weeks later, they claimed that they did not receive the fax (I had seen the confirmation page that the fax was sent successfully), and claimed they did not receive the letter. What bad luck, or was it just LIES?

    4. I emailed a copy of the documents as an attachment, and they replied that the “the documents which you have provided seems to be damaged one”. Not that the file was corrupted, or unreadable, but the documents were “damaged” (one). This is despite copying myself at a different address, and there was no “damage” in the file. Was this another LIE? In the email they asked the “documnet” be sent again.

    5. I re-faxed, re-posted, re-emailed the documents, and then they introduced the brand new requirement that the Notary had listed to be on a page that they could search on the Internet. This had never been mentioned before. Of course the individual Police Officer who had notarized it was not listed on a specific page, so Comodo did not accept him. You could fair say enough – but only if this was all specified previously, not after the job is done!

    6. So I had to find a notary that was listed on a webpage they had (the email said “please get sign from registered notary public”). The prices these guys charged ranged from $250 to $400! Nowhere on the Comodo site does it even hint that you will have to pay extra for a Notary. So I go through this trouble and $250 expense and the documents are faxed and mailed off again. I also emailed a copy which might have quickened things a little because it was only a week later that they ask me what is the best time for them to ring up the notary to check that he is really a notary! Not only do they want a notary to check that I am me, and that my documents are my documents, and that he is a notary, and that they can see he is a notary by sitting on their bums and checking the internet, but they want to ring him up and ask him if he really notarized it! And they want me to ring him up to arrange a time, rather than them ringing him up to arrange a time! Remember, this is another brand new requirement, not mentioned before.

    7. So I tell them to call him between 11am and 3pm Melbourne Australia time GMT +11hr, on weekdays. Comodo also wanted a time to call me (yet ANOTHER new requirement which had not been specified at any time earlier). I stated 6pm to 10pm Melbourne Australia time GMT +11hr. I offered to calculate the local time that would be for them, but not knowing where they were I could not. Two days later I chase them up. They say that they called the Notary but he “refused to confirm the signature”. I ring up the Notary, and he says that this is a LIE, and they have never called him or his secretary. As he takes his job very seriously, he in fact is very cross that these people are lying about him. I email Comodo back with this allegation and their STORY changes to “We made a call to the notary but he left for the day” (I have no information on why the secretary did not support this latest claim, but you might guess).

    8. After four more days and I chase them, and they say they called the Notary. Hoorah!!! Now they want to know what time they could call me to verify that I am me (apparently they did not trust the passport, the bank statement, and utility bill, that I am in the White Pages phone directory, the Notary, the notary being on a website, or what the Notary told them in a phone conversation). I naturally pointed out that I have already told them the time to call (6pm to 10pm Melbourne Australia time GMT +11hr). They said that they had tried to call me twice, but there was no answer. Another LIE - I am sure as I was home every evening that week, and no one rang.

    9. The next day my wife rang me up to say that these people, who she could barely understand, called me at home at 12 noon. Obviously I was at work, not home. They were Comodo people, from which country, and what intelligence I cannot say. I immediately emailed Comodo and pointed out (a little sarcastically) that for the third time they could ring 6pm to 10pm Melbourne Australia time GMT +11hr.

    10. This is just about the end, after exactly 40 days, I was rung up at the right time, struggled to understand the English spoken (approximately), stated I was me, and the code signing certificate was finally delivered.

    All I can say is never again, and I would never suggest people use any company that charges $71 and doesn’t tell you upfront about the other $250 you will have to spend. Fraudulent, incompetent, illiterate and dishonest.
  • (some HTML allowed)
    How does this make you feel?
    Add Image
    I'm

    e.g. sad, anxious, confused, frustrated happy, confident, thankful, excited kidding, amused, unsure, silly indifferent, undecided, unconcerned