TechKnowSurge
CompTIA Security+ 1.4 ISC2 CISSP 3.6 NIST 800-53 SC-17 Cisco CyberOps Associate 2.10 ISC2 CC 5.1 CompTIA SecurityX 2.2
InteractiveSecurityFree

Publisher, Timestamping Authority or Your Computer?

Code signing has three players. Who does each job: the publisher, the timestamping authority, or your computer?

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

When you download a program, you want to know it really is the program you meant to install, from the publisher you expect, and that nobody has changed it. Code signing gives you that. On Windows you see it in the User Account Control prompt as "Verified publisher", and you can open the publisher's certificate from there. It is the digital signature process with a program in place of a message. The publisher hashes the program to make a fingerprint and signs that fingerprint with its private key. You download the program, the signature and the publisher's certificate. Your computer verifies the certificate, hashes the program itself, and uses the public key in the certificate to check the signature against that fingerprint. If it verifies, the code came from that private key and has not changed. (The video calls signing "encrypting the hash" and checking "decrypting" it. That is a picture of RSA, not what a signature is: the private key signs, the public key verifies, and nothing is made secret.) Certificates expire. Without anything more, once a program's certificate has expired the user is told it is no longer valid, even if nothing is wrong with the program. Timestamping fixes that: it proves the signature existed while the certificate was still valid, so it stays acceptable into the future. A timestamping authority (TSA) is a trusted third party, much like a certificate authority. The video pictures the publisher handing it the whole package. In practice the publisher's signing tool sends only a fingerprint (hash) of the signature; the TSA puts that together with the time and signs it with its own private key. It has its own certificate, and your computer checks both certificates up to a trusted root certificate before it trusts either signature.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
ISC2 CISSP
3.6 Select and determine cryptographic solutions
NIST 800-53
SC-17 Public Key Infrastructure Certificates
Cisco CyberOps Associate
2.10 Describe the impact of certificates on security
ISC2 CC
5.1 Understand data security
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.

Key terms

Code Signing
The process of applying a digital signature to software using a certificate and private key so that users can verify the authenticity and integrity of downloaded programs.
Timestamping Authority
TSA
A trusted third party that issues cryptographically signed timestamps to prove that a code signature existed and was valid at a specific point in time, preserving trust after a certificate expires.
Digital Signature
A cryptographic mechanism used to verify the authenticity and integrity of a digital message or document.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.
Hash Function
A mathematical algorithm that converts input data of any size into a fixed-size output value used to verify data integrity.
Private Key
A secret cryptographic key used in asymmetric encryption to decrypt data or create digital signatures.
Public Key
A cryptographic key that can be shared openly and is used to encrypt data or verify digital signatures.
Public Key Infrastructure
PKI
A framework of hardware, software, policies, and standards used to create, manage, and distribute digital certificates.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Root Certificate
The self-signed certificate at the top of a PKI hierarchy that serves as the ultimate anchor of trust for all subordinate certificates.
User Account Control
UAC
A Windows security feature that limits the impact of malware by prompting users for permission or administrator credentials before allowing applications to make changes that require elevated privileges. UAC helps prevent unauthorized software from modifying system settings.

Topics

Code Signing Timestamping Authority Public Key Infrastructure Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →