Alex Rivera | Logout

Who should own the private key used to sign a .NET assembly when its project is open-source?

Asked 2010-01-07T15:51:41.450
27

More specifically, a class library assembly. My initial thoughts:

  • Have some designated administrators do all the assembly signing. But then when bug fixes and new versions are written, the binaries would ultimately depend on them being around (even if its just a small change for private reasons).
  • The key could be publicly available. But that goes against public-key cryptography practices and you lose the advantage of trust and identity.
  • Allow end-developers and distributors to sign it with their own keys. But then you lose modularization since each new signing makes it incompatible with some of the other versions.

Sure, you could just not sign the assembly. But if another project that requires their assembly to be signed references your library, you get a compile error.

Edit
Report

2 Answers

2

The question really revolves around who decides what is a release, doesn't it? If that is so, I think the releases should be signed with a personal key of the one actually being responsible for the release. If there are multiple persons responsible for creating releases there is nothing wrong with them sharing the key, except for higher risks of having to revoke/re-issue the key if one of the members of this group leaves.

In a broader scope, one has to admit, that .net doesn't really cater for re-using assemblies between multiple installed applications. Look into your SxS folder! So another way would always be for the distributor of the assembly to sign it with his own key. e.g. if a project uses log4net, it should sign the log4net assembly with its own key to take responsibility for its contents.

answered 2010-01-07T16:05:22.250
1

In Open Source, the "source" is open. Binaries are usually provided only for commodity.

Source does not need to be signed, if the binary is signed then the generator of the binary is also the owner of the secret key (which shall be kept secret).

answered 2010-01-07T16:05:01.737

Your Answer