Skip to content

Conversation

nasantia
Copy link

Adding verbiage to set new code signing certificate validity to 460 days

Updating to mostly match ian's original verbiage. However, given that we want at least 6 months to reflect the change after enforcmeent, setting the date to January 1st of 2026 instead of the original June 15th of 2025
removing previous line to avoid confusion, and updating to March
Update CSBR.md for proposed validity period change
@@ -2029,7 +2029,7 @@ CAs SHALL ensure that the Subscriber’s Private Key is generated, stored, and u

Subscribers and Signing Services MAY sign Code at any point in the development or distribution process. Code Signatures may be verified at any time, including during download, unpacking, installation, reinstallation, or execution, or during a forensic investigation.

The validity period for a Code Signing Certificate issued to a Subscriber or Signing Service MUST NOT exceed 39 months.
For all Code Signing Certificates issued after March 1st, 2026, the validity period for the Code Signing Certificate issued to a Subscriber MUST NOT exceed 460 days.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
For all Code Signing Certificates issued after March 1st, 2026, the validity period for the Code Signing Certificate issued to a Subscriber MUST NOT exceed 460 days.
For Code Signing Certificates issued before March 1st, 2026, the validity period MUST NOT exceed 39 months. For Code Signing Certificates issued on or after March 1st, 2026, the validity period MUST NOT exceed 460 days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants