Closed
Description
The code signing certificate we use for Windows (obtained in 2020) is expiring on 18 December 2023. We've now got a reminder email through to the accounts email alias from DigiCert.
We'd need to go through the OpenJS Foundation for payment (cc @bensternthal). This might be a good opportunity to hand this bit (the certificate ownership/renewal) over to the Linux Foundation as part of the longer term discussions around the Sovereign Tech Fund initiative.
If we continue with DigiCert, we need to be aware of (based on what we're currently doing):
- [DigiCert] 2FA will be turned on for your account #3453 -- I've not signed into the account and am not sure anyone else has. We'd need to set up 2FA and add the necessary details to the secrets repo.
- Code signing cert changes #2646 -- we'll need to use a larger key size (our instructions in the secrets repo say to use a 2048-bit RSA key size but the DigiCert notification in Code signing cert changes #2646 says renewals will need to use a larger one).
- I wasn't involved last time, but it sounded like there was some verification process involving DigiCert calling a Foundation number.
Once we have a new signing certificate we'd need to install it on all of the Windows release machines (cc @StefanStojanovic ).