How do I verify short-lived code signing certificates for executables, DLLs, and JARs?

Last reviewed: 3/25/2025

HowTo Article ID: H032508

The information in this article applies to:

  • Chant Developer Workbench 2025
  • AudioSearch 6
  • GrammarKit 11
  • KinesicsKit 9
  • LexiconKit 11
  • ProfileKit 11
  • SpeechKit 14
  • SpeechManager 5
  • Talk&Listen 6
  • VoiceMarkupKit 11
  • VoiceXMLKit 8

Summary

Chant has migrated EXE, DLL, and JAR code signing to Microsoft Trusted Signing.

More Information

To help reduce the impact of signing misuse and abuse, Trusted Signing short-lived certificates are renewed daily and are valid for only 72 hours. There are several advantages to this approach.

Subscriber identity validation EKU

Trusted Signing provides a durable identity value in each certificate that is associated with the subscription's identity validation resource. The durable identity value is a custom EKU.

Zero-touch certificate lifecycle management

The Trusted Signing zero-touch certificate lifecycle management feature automatically handles all standard certificate actions.

Time stamp countersignatures

The standard practice in signing is to countersign all signatures with an RFC 3161-compliant time stamp. Because Trusted Signing uses short-lived certificates, time stamp countersigning is critical for a signature to be valid beyond the life of the signing certificate.

Active monitoring

Trusted Signing supports active threat intelligence monitoring by constantly looking for cases of misuse and abuse of Trusted Signing subscribers' Public Trust certificates.

To verify an EXE, DLL, and JAR file, review the steps described in H032311 CDW 2023 verifying code signing certificates for EXEs, DLLs, and JARs.