Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Signed binaries. #157

Open
BenAveling opened this issue Aug 12, 2022 · 3 comments
Open

Signed binaries. #157

BenAveling opened this issue Aug 12, 2022 · 3 comments
Labels
ci CI/CD and release automation deployment

Comments

@BenAveling
Copy link

Would it be possible to sign the released binaries?

Without a signature, Pomerium is getting blocked by end point protection software, and quarantined.

Unknown Publisher...
... prevented an unrecognized app from running.

@desimone
Copy link
Contributor

@BenAveling can you provide a bit more details on your environment?

  • What binaries?
  • What operating system?
  • What architecture?
  • Version of pomerium?
  • etc

Thanks!

@desimone desimone added the NeedsMoreData Waiting for additional user feedback or case studies label Aug 12, 2022
@BenAveling
Copy link
Author

What binaries?

Immediate issue is Pomerium desktop, but I understand CLI client is the same.

What operating system?

Windows.

What architecture?

64 bit, but I'm sure it doesn't matter.

Version of pomerium?

Observed with 0.17.1 and 0.18.0. Presumably others.

Etc....

This is what the properties for a random signed binary looks like:
image

Pomerium binaries are lacking that tab (because they aren't signed)

image

Because the binary is unsigned/unknown/untrusted, this can cause malware detection to trigger, and either block, or even quarantine (delete) the binary:

image

image

@BenAveling
Copy link
Author

We've asked our vendor to allow-list this release.

Once enough other customers do the same, this will stop being a problem, for this release.

image

@desimone desimone added ci CI/CD and release automation deployment and removed NeedsMoreData Waiting for additional user feedback or case studies labels Aug 15, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci CI/CD and release automation deployment
Projects
None yet
Development

No branches or pull requests

2 participants