Read-only archive of the All About Symbian forum (2001–2013) · About this archive

ACS Publisher ID

10 replies · 1 views · Started 23 January 2006

Hi,

We need to sign a client's application, for this the client has given us
a .pfx file from Verisign! I believe I can't sign the sis with this pfx
file. What is it that I actually need from Verisign to sign the sis and
how do I extract the required ID from this pfx?

AMK

AMK wrote:
> Hi,
>
> We need to sign a client's application, for this the client has given us
> a .pfx file from Verisign! I believe I can't sign the sis with this pfx
> file. What is it that I actually need from Verisign to sign the sis and
> how do I extract the required ID from this pfx?
>
> AMK

Got this done.

The info on the symbian signed website is a little confusing.
From the page https://www.symbiansigned.com/app/page/process

Sequence of events... event no. 5

---------------------------------------
"Developer downloads a tool for exporting their ACS Publisher ID to a
standard format for use with Makesis"
---------------------------------------

I looked all around the site for this tool but didn't find it. I then
tried at the Verisign site, FAQs and there it was.

AMK

> I looked all around the site for this tool but didn't find it. I then
> tried at the Verisign site, FAQs and there it was.
>
> AMK

Hello AMK,
which Verisign site or tool is it?
Thanks.
--
Tobias
www.OutBank.de

Hi,

the tool to "convert" from pfx to proper key/cert pair is downloable in:

http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/page_002759.html

This works. However, what else needs to be done so the initial installation
warning is removed? The certificate appears ok. Do I need to send the "sis"
file to verisign so the thay can sign it?

Cheers in advance,

Cronopi

"AMK" <[email protected]> escribi� en el mensaje
news:KVlEHs16FHA.2708@extapps30...
> Hi,
>
> We need to sign a client's application, for this the client has given us a
> .pfx file from Verisign! I believe I can't sign the sis with this pfx
> file. What is it that I actually need from Verisign to sign the sis and
> how do I extract the required ID from this pfx?
>
> AMK

You have to get your sis Symbian Signed. Go to www.symbiansigned.com to
get full details on how to achieve this?

AMK

cronopi wrote:
> Hi,
>
> the tool to "convert" from pfx to proper key/cert pair is downloable in:
>
> http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/page_002759.html
>
> This works. However, what else needs to be done so the initial installation
> warning is removed? The certificate appears ok. Do I need to send the "sis"
> file to verisign so the thay can sign it?
>
> Cheers in advance,
>
> Cronopi
>
>
> "AMK" <[email protected]> escribi� en el mensaje
> news:KVlEHs16FHA.2708@extapps30...[color=green]
>> Hi,
>>
>> We need to sign a client's application, for this the client has given us a
>> .pfx file from Verisign! I believe I can't sign the sis with this pfx
>> file. What is it that I actually need from Verisign to sign the sis and
>> how do I extract the required ID from this pfx?
>>
>> AMK

>
>[/color]

Thanx AMK for answering but I'm not talking about symbian 9.x. (Sorry for
not mentioning that) I will eventually need to sign a S60 3rd ed application
but now it's just about signing (and not showing warning messages) S60 2.X
and UIQ 2.X applications...

For what I read, in sdk help (Symbian 7.0), I need to
[I quote]

1.. Create a certificate request using the Certificate Generator,
specifying the private key and self-signed certificate created in step 1.

2.. Send the certificate request to the Certificate Authority, and get
back the authenticated digital certificate.

[end quote]

However, in verisign website, I understand that I have to send my sis file
so it can be "re-signed"...

Any help is very welcome!!!!

"AMK" <[email protected]> escribi� en el mensaje
news:dBPiRUXWGHA.2792@extapps30...
> You have to get your sis Symbian Signed. Go to www.symbiansigned.com to
> get full details on how to achieve this?
>
> AMK
>
> cronopi wrote:[color=green]
>> Hi,
>>
>> the tool to "convert" from pfx to proper key/cert pair is downloable in:
>>
>> http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/page_002759.html
>>
>> This works. However, what else needs to be done so the initial
>> installation warning is removed? The certificate appears ok. Do I need to
>> send the "sis" file to verisign so the thay can sign it?
>>
>> Cheers in advance,
>>
>> Cronopi
>>
>>
>> "AMK" <[email protected]> escribi� en el mensaje
>> news:KVlEHs16FHA.2708@extapps30...[color=darkred]
>>> Hi,
>>>
>>> We need to sign a client's application, for this the client has given us
>>> a .pfx file from Verisign! I believe I can't sign the sis with this pfx
>>> file. What is it that I actually need from Verisign to sign the sis and
>>> how do I extract the required ID from this pfx?
>>>
>>> AMK

>>[/color][/color]

To get rid of the warning message you have to get the sis signed. Even
on the pre SOS 9.x platform.

AMK

cronopi wrote:
> Thanx AMK for answering but I'm not talking about symbian 9.x. (Sorry for
> not mentioning that) I will eventually need to sign a S60 3rd ed application
> but now it's just about signing (and not showing warning messages) S60 2.X
> and UIQ 2.X applications...
>
> For what I read, in sdk help (Symbian 7.0), I need to
> [I quote]
>
> 1.. Create a certificate request using the Certificate Generator,
> specifying the private key and self-signed certificate created in step 1.
>
> 2.. Send the certificate request to the Certificate Authority, and get
> back the authenticated digital certificate.
>
> [end quote]
>
> However, in verisign website, I understand that I have to send my sis file
> so it can be "re-signed"...
>
> Any help is very welcome!!!!
>
> "AMK" <[email protected]> escribi� en el mensaje
> news:dBPiRUXWGHA.2792@extapps30...[color=green]
>> You have to get your sis Symbian Signed. Go to www.symbiansigned.com to
>> get full details on how to achieve this?
>>
>> AMK
>>
>> cronopi wrote:[color=darkred]
>>> Hi,
>>>
>>> the tool to "convert" from pfx to proper key/cert pair is downloable in:
>>>
>>> http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/page_002759.html
>>>
>>> This works. However, what else needs to be done so the initial
>>> installation warning is removed? The certificate appears ok. Do I need to
>>> send the "sis" file to verisign so the thay can sign it?
>>>
>>> Cheers in advance,
>>>
>>> Cronopi
>>>
>>>
>>> "AMK" <[email protected]> escribi� en el mensaje
>>> news:KVlEHs16FHA.2708@extapps30...
>>>> Hi,
>>>>
>>>> We need to sign a client's application, for this the client has given us
>>>> a .pfx file from Verisign! I believe I can't sign the sis with this pfx
>>>> file. What is it that I actually need from Verisign to sign the sis and
>>>> how do I extract the required ID from this pfx?
>>>>
>>>> AMK
[/color]
>[/color]

.... by sending the sis to (e.g.) verisign?

I would also need to automate somehow the signing process. Is there anyway
to sign it locally?

Thanks again!

Cronopi.

"AMK" <[email protected]> escribi� en el mensaje
news:vg1WX9XWGHA.2792@extapps30...
> To get rid of the warning message you have to get the sis signed. Even on
> the pre SOS 9.x platform.
>
> AMK
>
> cronopi wrote:[color=green]
>> Thanx AMK for answering but I'm not talking about symbian 9.x. (Sorry for
>> not mentioning that) I will eventually need to sign a S60 3rd ed
>> application but now it's just about signing (and not showing warning
>> messages) S60 2.X and UIQ 2.X applications...
>>
>> For what I read, in sdk help (Symbian 7.0), I need to
>> [I quote]
>>
>> 1.. Create a certificate request using the Certificate Generator,
>> specifying the private key and self-signed certificate created in step 1.
>>
>> 2.. Send the certificate request to the Certificate Authority, and get
>> back the authenticated digital certificate.
>>
>> [end quote]
>>
>> However, in verisign website, I understand that I have to send my sis
>> file so it can be "re-signed"...
>>
>> Any help is very welcome!!!!
>>
>> "AMK" <[email protected]> escribi� en el mensaje
>> news:dBPiRUXWGHA.2792@extapps30...[color=darkred]
>>> You have to get your sis Symbian Signed. Go to www.symbiansigned.com to
>>> get full details on how to achieve this?
>>>
>>> AMK
>>>
>>> cronopi wrote:
>>>> Hi,
>>>>
>>>> the tool to "convert" from pfx to proper key/cert pair is downloable
>>>> in:
>>>>
>>>> http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/page_002759.html
>>>>
>>>> This works. However, what else needs to be done so the initial
>>>> installation warning is removed? The certificate appears ok. Do I need
>>>> to send the "sis" file to verisign so the thay can sign it?
>>>>
>>>> Cheers in advance,
>>>>
>>>> Cronopi
>>>>
>>>>
>>>> "AMK" <[email protected]> escribi� en el mensaje
>>>> news:KVlEHs16FHA.2708@extapps30...
>>>>> Hi,
>>>>>
>>>>> We need to sign a client's application, for this the client has given
>>>>> us a .pfx file from Verisign! I believe I can't sign the sis with this
>>>>> pfx file. What is it that I actually need from Verisign to sign the
>>>>> sis and how do I extract the required ID from this pfx?
>>>>>
>>>>> AMK

>>[/color][/color]

http://www.symbiansigned.com

AMK

cronopi wrote:
> ... by sending the sis to (e.g.) verisign?
>
> I would also need to automate somehow the signing process. Is there anyway
> to sign it locally?
>
> Thanks again!
>
> Cronopi.
>
>
> "AMK" <[email protected]> escribi� en el mensaje
> news:vg1WX9XWGHA.2792@extapps30...[color=green]
>> To get rid of the warning message you have to get the sis signed. Even on
>> the pre SOS 9.x platform.
>>
>> AMK
>>
>> cronopi wrote:[color=darkred]
>>> Thanx AMK for answering but I'm not talking about symbian 9.x. (Sorry for
>>> not mentioning that) I will eventually need to sign a S60 3rd ed
>>> application but now it's just about signing (and not showing warning
>>> messages) S60 2.X and UIQ 2.X applications...
>>>
>>> For what I read, in sdk help (Symbian 7.0), I need to
>>> [I quote]
>>>
>>> 1.. Create a certificate request using the Certificate Generator,
>>> specifying the private key and self-signed certificate created in step 1.
>>>
>>> 2.. Send the certificate request to the Certificate Authority, and get
>>> back the authenticated digital certificate.
>>>
>>> [end quote]
>>>
>>> However, in verisign website, I understand that I have to send my sis
>>> file so it can be "re-signed"...
>>>
>>> Any help is very welcome!!!!
>>>
>>> "AMK" <[email protected]> escribi� en el mensaje
>>> news:dBPiRUXWGHA.2792@extapps30...
>>>> You have to get your sis Symbian Signed. Go to www.symbiansigned.com to
>>>> get full details on how to achieve this?
>>>>
>>>> AMK
>>>>
>>>> cronopi wrote:
>>>>> Hi,
>>>>>
>>>>> the tool to "convert" from pfx to proper key/cert pair is downloable
>>>>> in:
>>>>>
>>>>> http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/page_002759.html
>>>>>
>>>>> This works. However, what else needs to be done so the initial
>>>>> installation warning is removed? The certificate appears ok. Do I need
>>>>> to send the "sis" file to verisign so the thay can sign it?
>>>>>
>>>>> Cheers in advance,
>>>>>
>>>>> Cronopi
>>>>>
>>>>>
>>>>> "AMK" <[email protected]> escribi� en el mensaje
>>>>> news:KVlEHs16FHA.2708@extapps30...
>>>>>> Hi,
>>>>>>
>>>>>> We need to sign a client's application, for this the client has given
>>>>>> us a .pfx file from Verisign! I believe I can't sign the sis with this
>>>>>> pfx file. What is it that I actually need from Verisign to sign the
>>>>>> sis and how do I extract the required ID from this pfx?
>>>>>>
>>>>>> AMK
[/color]
>
>[/color]

Thanks AMK. I know about Symbian Signed but I wrongly assumed that by adding
"a" proper certificate (purchased at e.g. verisign) in the sis file (as the
Symbian SDK Documentation states) the warning would be removed. I knew that
on S60 3rd Edition that wasn't the case but I didn't for earlier releases.

Has anybody also found the documentation misleading?

"AMK" <[email protected]> escribi� en el mensaje
news:CgvSYJjWGHA.2608@extapps30...
> http://www.symbiansigned.com
>
> AMK
>
> cronopi wrote:[color=green]
>> ... by sending the sis to (e.g.) verisign?
>>
>> I would also need to automate somehow the signing process. Is there
>> anyway to sign it locally?
>>
>> Thanks again!
>>
>> Cronopi.
>>
>>
>> "AMK" <[email protected]> escribi� en el mensaje
>> news:vg1WX9XWGHA.2792@extapps30...[color=darkred]
>>> To get rid of the warning message you have to get the sis signed. Even
>>> on the pre SOS 9.x platform.
>>>
>>> AMK
>>>
>>> cronopi wrote:
>>>> Thanx AMK for answering but I'm not talking about symbian 9.x. (Sorry
>>>> for not mentioning that) I will eventually need to sign a S60 3rd ed
>>>> application but now it's just about signing (and not showing warning
>>>> messages) S60 2.X and UIQ 2.X applications...
>>>>
>>>> For what I read, in sdk help (Symbian 7.0), I need to
>>>> [I quote]
>>>>
>>>> 1.. Create a certificate request using the Certificate Generator,
>>>> specifying the private key and self-signed certificate created in step
>>>> 1.
>>>>
>>>> 2.. Send the certificate request to the Certificate Authority, and
>>>> get back the authenticated digital certificate.
>>>>
>>>> [end quote]
>>>>
>>>> However, in verisign website, I understand that I have to send my sis
>>>> file so it can be "re-signed"...
>>>>
>>>> Any help is very welcome!!!!
>>>>
>>>> "AMK" <[email protected]> escribi� en el mensaje
>>>> news:dBPiRUXWGHA.2792@extapps30...
>>>>> You have to get your sis Symbian Signed. Go to www.symbiansigned.com
>>>>> to get full details on how to achieve this?
>>>>>
>>>>> AMK
>>>>>
>>>>> cronopi wrote:
>>>>>> Hi,
>>>>>>
>>>>>> the tool to "convert" from pfx to proper key/cert pair is downloable
>>>>>> in:
>>>>>>
>>>>>> http://www.verisign.com/products-services/security-services/code-signing/symbian-content-signing/page_002759.html
>>>>>>
>>>>>> This works. However, what else needs to be done so the initial
>>>>>> installation warning is removed? The certificate appears ok. Do I
>>>>>> need to send the "sis" file to verisign so the thay can sign it?
>>>>>>
>>>>>> Cheers in advance,
>>>>>>
>>>>>> Cronopi
>>>>>>
>>>>>>
>>>>>> "AMK" <[email protected]> escribi� en el mensaje
>>>>>> news:KVlEHs16FHA.2708@extapps30...
>>>>>>> Hi,
>>>>>>>
>>>>>>> We need to sign a client's application, for this the client has
>>>>>>> given us a .pfx file from Verisign! I believe I can't sign the sis
>>>>>>> with this pfx file. What is it that I actually need from Verisign to
>>>>>>> sign the sis and how do I extract the required ID from this pfx?
>>>>>>>
>>>>>>> AMK

>>[/color][/color]