Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Suggestion] Add Code Signing Certificates to policy #263

Open
Matthew-Cherry87 opened this issue Jul 14, 2023 · 1 comment
Open

[Suggestion] Add Code Signing Certificates to policy #263

Matthew-Cherry87 opened this issue Jul 14, 2023 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@Matthew-Cherry87
Copy link

Matthew-Cherry87 commented Jul 14, 2023

It would be great if the WDAC wizard allowed for the importing of code signing certificates for signing binary files.

When creating a new WDAC Policy requiring signed system integrity policy, we still need to manually run the Add-SignerRule cmdlet to add the authorised code signing certificates.

It'd be great if signer rules could be created as custom rule conditions OR when a user disables unsigned integrity policy within the Policy Rules page a prompt is automatically created requesting the user to select the code signing certificates they wish to add.

Appreciate the work!

@jgeurten jgeurten self-assigned this Jul 17, 2023
@jgeurten jgeurten added the enhancement New feature or request label Jul 17, 2023
@jgeurten
Copy link
Contributor

I love both suggestions! This lack of this experience is the reason for hardcoding that policies must have the unsigned option set since converting to binary file will fail without a PolicySigners section

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants