YubiKey Code-Signing Setup Help
Budget: £20 – £250 GBP
I have three "Yubikey 5C FIPS" keys. One is not reachable right now, so effectively only two.
I have a "(company name).crt" file from DigiCert.
ChatGPT tells me that I have set up the keys correctly with the private key in the FIPS store, on Linux Mint.
I have a Windows VM that I want to use to make/build and sign .exe files.
I need help with:
a. Verifying that I have indeed set up the two keys correctly, and fixing them if they are not okay,
b. Setting up code signing on the VM,
c. Verifying that both keys can sign code.
How:
1. We will work using meet.google.com.
2. You will need reasonable English.
3. I will share my screen and get you to tell me what to do (security!)(*)
4. I won't agree to milestone payments. This should be a quick process.
5. Don't make an initial low bid to get the work. I won't agree a higher price later.
6. I will pay you in full as soon as two keys are able to code sign my executable.
I am happy to resolve any doubts about my setup by running diagnostic commands during the bid stage.
I have implemented ECC encryption rather than RSA, which I think means I need to use osslsigncode rather than signtool.
* I am a software engineer. I will cooperate as fully as I am able, subject to security.
I have a "(company name).crt" file from DigiCert.
ChatGPT tells me that I have set up the keys correctly with the private key in the FIPS store, on Linux Mint.
I have a Windows VM that I want to use to make/build and sign .exe files.
I need help with:
a. Verifying that I have indeed set up the two keys correctly, and fixing them if they are not okay,
b. Setting up code signing on the VM,
c. Verifying that both keys can sign code.
How:
1. We will work using meet.google.com.
2. You will need reasonable English.
3. I will share my screen and get you to tell me what to do (security!)(*)
4. I won't agree to milestone payments. This should be a quick process.
5. Don't make an initial low bid to get the work. I won't agree a higher price later.
6. I will pay you in full as soon as two keys are able to code sign my executable.
I am happy to resolve any doubts about my setup by running diagnostic commands during the bid stage.
I have implemented ECC encryption rather than RSA, which I think means I need to use osslsigncode rather than signtool.
* I am a software engineer. I will cooperate as fully as I am able, subject to security.