Alex Rivera | Logout

Best practices for signing .NET assemblies?

Asked 2008-08-29T21:48:32.603
46

I have a solution consisting of five projects, each of which compile to separate assemblies. Right now I'm code-signing them, but I'm pretty sure I'm doing it wrong. What's the best practice here?

  • Sign each with a different key; make sure the passwords are different
  • Sign each with a different key; use the same password if you want
  • Sign each with the same key
  • Something else entirely

Basically I'm not quite sure what "signing" does to them, or what the best practices are here, so a more generally discussion would be good. All I really know is that FxCop yelled at me, and it was easy to fix by clicking the "Sign this assembly" checkbox and generating a .pfx file using Visual Studio (2008).

Edit
Report

1 Answer

3

It is important to keep your PFX file secret as it contains the private key.

If that key is made available to others then anyone can sign assemblies or programs that masquerade as you.

To associate your name with your assemblies (in the eyes of Windows) you'll need to get a digital certificate (the portion of the PFX file containing your name) signed by a trusted authority.

Actually you'll get a new certificate, but with the same information.

You'll have to pay for this certificate (probably annually), but the certificate authority will effectively vouch for your existence (after you've faxed them copies of your passport or driver's permit and a domestic bill).

answered 2008-09-11T09:23:27.323

Your Answer