Add automatic AuthRoot cache for portable trust#24
Merged
Marc-André Moreau (mamoreau-devolutions) merged 1 commit intoJun 25, 2026
Merged
Conversation
Add a portable AuthRoot cache resolver with stale refresh and environment overrides, wire it into portable trust verification, and align the PowerShell module cache behavior. Normalize exact duplicate certificates in Authenticode SignedData certificate bags so Windows-valid Azure Artifact Signing signatures parse in the strict Rust CMS stack. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
5fa8cb2
into
master
36 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
--mode portable verifycalls through portable trust verification by default when auto trust is enabled, and align the PowerShell module cache behavior.SignedData.certificatesbags so Windows-valid Azure Artifact Signing signatures parse in the strict Rust CMS stack.Validation
cargo build --lockedcargo clippy --workspace --all-targets --lockedcargo test -p psign-sip-digest pkcs7_wire --lockedcargo test -p psign-authenticode-trust --lib --lockedcargo test -p psign-authenticode-trust authroot_cache --lockeddotnet build dotnet/Devolutions.Psign.PowerShell/Devolutions.Psign.PowerShell.csprojbash scripts/linux-portable-validation.shpsign-tool --mode portable verify tursodb.exewith a fresh AuthRoot cacheKnown baseline: full
cargo test --workspace --lockedstill fails on the existingtests/fixtures/msix-minimal/AppxManifest.xmlfixture manifest-size mismatch.