{"id":163,"date":"2021-10-22T00:00:00","date_gmt":"2021-10-22T00:00:00","guid":{"rendered":"https:\/\/codesigncert.com\/resourcesnew\/sha1-sha-256-dual-signing\/"},"modified":"2026-08-02T08:10:05","modified_gmt":"2026-08-02T08:10:05","slug":"sha1-sha-256-dual-signing","status":"publish","type":"resources","link":"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing","title":{"rendered":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 ez-toc-wrap-right counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/#Learn_about_SH1_SHA-256_SHA2_Dual-signing_and_Code_Signing\" >Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/#So_What_is_The_Actual_Truth_%E2%80%93_Explained_in_detail\" >So What is The Actual Truth? &#8211; Explained in detail<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/#What_are_the_versions_of_Windows_Support_SHA-256_signatures\" >What are the versions of Windows Support SHA-256 signatures?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/#What_About_All_Supporting_Versions_of_Windows_That_Do_Not_Support_SHA-256\" >What About All Supporting Versions of Windows That Do Not Support SHA-256?<\/a><\/li><\/ul><\/nav><\/div>\n<div class=\"col-lg-12 mb-3 p-2\">\n<h2><span class=\"ez-toc-section\" id=\"Learn_about_SH1_SHA-256_SHA2_Dual-signing_and_Code_Signing\"><\/span>Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>With effect from 30th May 2020, SHA1 timestamping is deprecated because the SHA1 roots have got expired. So it is highly recommended to use only the SHA256 timestamp server from now onwards. Also, Microsoft has announced a SHA256 transition a few years ago. This means that all the Windows software developers must be compulsorily onboard as of Jan 1, 2016.<\/p>\n<p>The <a href=\"http:\/\/aka.ms\/sha1\">Microsoft PKI Blog<\/a> speaks it all. The blog discusses, in brief, the Windows and Windows Server that has discontinued putting trust on the new code signed with an SHA-1 code signing certificate for various scenarios such as files containing a digital signature. Also for those certificates that have been time-stamped with a value above than 1st January 2016. These restrictions will not apply to the time-stamp certificate used to time-stamp the code-signing certificate or certificate&rsquo;s signature hash until 1st January 2017. Post this time, all the codes with an SHA-1 time-stamp or SHA-1 signature hash shall be considered non-existent and without a time-stamp signature by the Windows.<\/p>\n<div style=\"width: 100%; float: left; margin: 30px 0; border: 5px solid #d6d6d6; border-radius: 5px;\">\n<div style=\"width: 100%; float: left; background-color: #108ab3;\">\n<div class=\"container\" style=\"text-align: center;\">\n<div style=\"padding-left: 20px;\">\n<h3 style=\"font-size: 24px; text-decoration: underline; line-height: 30px; color: #ffffff; font-weight: bold; padding: 15px 0;\"><a href=\"https:\/\/codesigncert.com\/comodo-code-signing-certificate\" target=\"_blank\" style=\"color: #fff;\"> Buy Comodo Code Signing Certificate at Only $59 Per Year <\/a><\/h3>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"clear\"><\/div>\n<h2><span class=\"ez-toc-section\" id=\"So_What_is_The_Actual_Truth_%E2%80%93_Explained_in_detail\"><\/span>So What is The Actual Truth? &#8211; Explained in detail<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>That any files signed with an SHA-1 certificate need to have a timestamp showing date and time before Jan 1, 2016, to continue to be supported. Those files will still be allowed through the &#8216;Mark-of-the-web&#8221; system until Jan 14, 2020, when all SHA-1 support will stop in all current versions of Windows. Any new signatures created or timestamped after Jan 1, 2016, must be SHA-256 based signatures or they will cause a &#8220;digital signature is corrupted or invalid&#8221; error when downloading.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_are_the_versions_of_Windows_Support_SHA-256_signatures\"><\/span>What are the versions of Windows Support SHA-256 signatures?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>SHA-256 signatures are not supported in Windows XP SP2 or earlier. SHA-256 is only supported in User Mode for Windows XP SP 3, Vista, and Windows Server 2008R1 &#8212; SHA-256 certificates are not supported for drivers on any version before Windows 7.<\/p>\n<p>In order to support Windows XP SP3 and Windows Vista you need to dual sign and include an SHA1 file digest. Like this :<\/p>\n<p><strong><em>signtool.exe sign \/f MyCert.pfx \/p &lt;PFX password&gt;&nbsp; \/t http:\/\/timestamp.&lt;COMPANYNAME&gt;.com \/v foo.exe<\/em><\/strong><\/p>\n<p><strong><em>signtool.exe sign \/f MyCert.pfx \/p &lt;PFX password&gt; \/fd sha256 \/tr http:\/\/timestamp.&lt;COMPANYNAME&gt;.com\/?td=sha256 \/td sha256 \/as \/v foo.exe<\/em><\/strong><\/p>\n<p>Run BOTH of those signtool.exe commands.<\/p>\n<p><em>*** Note that you may need to pass additional arguments to signtool.exe &#8212; like a password to decrypt the PFX\/P12 file.<\/em><\/p>\n<p><em>Note that you do need the 6.3 version of Signtool to do this. It comes with the Windows 8.1 SDK, or download it here. <\/em>&lt;LINK OF THE COMPANY ATTACHED&gt;<\/p>\n<p>If you want to include a FULL SHA1 signature (to support even older Windows versions) &#8211; use two different certificates&nbsp; :<\/p>\n<p><strong><em>signtool.exe sign \/f MySHA1Cert.pfx \/p &lt;PFX password&gt; \/t http:\/\/timestamp.&lt;COMPANY NAME&gt;.com \/v foo.exe<\/em><\/strong><\/p>\n<p><strong><em>signtool.exe sign \/f MySHA256Cert.pfx \/p &lt;PFX password&gt; \/fd sha256 \/tr http:\/\/timestamp.&lt;COMPANYNAME&gt;.com\/?td=sha256 \/td sha256 \/as \/v foo.exe<\/em><\/strong><\/p>\n<p><em>Click here to read more about &lt;COMPANAYNAME AND LINK&gt;<\/em><\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_About_All_Supporting_Versions_of_Windows_That_Do_Not_Support_SHA-256\"><\/span>What About All Supporting Versions of Windows That Do Not Support SHA-256?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>If you want to support Windows XP SP2 or earlier, you should dual-sign your EXEs, DLLs, and other files. This will require an SHA-1 based certificate**<\/p>\n<p>If you wish to dual-sign you may do so with the 6.3 version of signtool that comes with Windows 8.1 SDK&nbsp;<\/p>\n<p><strong><em>signtool.exe sign \/f MyCert.pfx&nbsp; \/t &lt;URL to SHA-1 Authenticode timestamp server&gt; \/v foo.exe<\/em><\/strong><\/p>\n<p><strong><em>signtool.exe sign \/f MyCert.pfx \/fd sha256 \/tr &lt;URL to SHA-2 RFC-3161 timestamp server&gt; \/td sha256 \/as \/v foo.exe<\/em><\/strong><\/p>\n<p><em>* Note that you may need to pass additional arguments to signtool.exe &#8212; like a password to decrypt the PFX\/P12 file.<\/em><\/p>\n<p><strong><em>For SHA-256 timestamps, use Comodo&#8217;s SHA256 timestamp server: http:\/\/timestamp.&lt;COMPANYNAME&gt;.com\/?td=sha256<\/em><\/strong><\/p>\n<p>If your users are getting an error message that reads &#8220;The signature of this program is corrupt or invalid&#8221; when they download, you need to upgrade to an SHA-256 signature!<\/p>\n<\/p><\/div>\n<div class=\"col-lg-12 mt-5 mb-4\">\n<h4 class=\"text-primary mb-4 pb-2 border-bottom\">Related Articles<\/h4>\n<div class=\"row g-4\">\n","protected":false},"excerpt":{"rendered":"<p>With effect from 30th May 2020, SHA1 timestamping is deprecated because the SHA1 roots have got expired. So it is highly recommended to use only the SHA256 timestamp server from now onwards. Also, Microsoft has announced a SHA256 transition a few years ago. This means that all the Windows software developers must be compulsorily onboard as of Jan 1, 2016.<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"resources_category":[50],"class_list":["post-163","resources","type-resources","status-publish","hentry","resources_category-code-signing-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates<\/title>\n<meta name=\"description\" content=\"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates and Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates\" \/>\n<meta property=\"og:description\" content=\"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates and Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing\" \/>\n<meta property=\"og:url\" content=\"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/\" \/>\n<meta property=\"og:site_name\" content=\"CodeSignCert\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/codesigncert\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-02T08:10:05+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@codesigncert\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/sha1-sha-256-dual-signing\\\/\",\"url\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/sha1-sha-256-dual-signing\\\/\",\"name\":\"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#website\"},\"datePublished\":\"2021-10-22T00:00:00+00:00\",\"dateModified\":\"2026-08-02T08:10:05+00:00\",\"description\":\"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates and Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/sha1-sha-256-dual-signing\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/codesigncert.com\\\/resources\\\/sha1-sha-256-dual-signing\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/sha1-sha-256-dual-signing\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Resources\",\"item\":\"https:\\\/\\\/codesigncert.com\\\/?post_type=resources\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/\",\"name\":\"CodeSignCert\",\"description\":\"All in One Code Signing Certificate Store\",\"alternateName\":\"Code Sign Cert\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates","description":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates and Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates","og_description":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates and Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing","og_url":"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/","og_site_name":"CodeSignCert","article_publisher":"https:\/\/www.facebook.com\/codesigncert","article_modified_time":"2026-08-02T08:10:05+00:00","twitter_card":"summary_large_image","twitter_site":"@codesigncert","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/","url":"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/","name":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates","isPartOf":{"@id":"https:\/\/codesigncert.com\/blog\/#website"},"datePublished":"2021-10-22T00:00:00+00:00","dateModified":"2026-08-02T08:10:05+00:00","description":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates and Learn about SH1, SHA-256, SHA2, Dual-signing and Code Signing","breadcrumb":{"@id":"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/codesigncert.com\/resources\/sha1-sha-256-dual-signing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/codesigncert.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Resources","item":"https:\/\/codesigncert.com\/?post_type=resources"},{"@type":"ListItem","position":3,"name":"The truth about SHA1, SHA-256, dual-signing, and Code Signing Certificates"}]},{"@type":"WebSite","@id":"https:\/\/codesigncert.com\/blog\/#website","url":"https:\/\/codesigncert.com\/blog\/","name":"CodeSignCert","description":"All in One Code Signing Certificate Store","alternateName":"Code Sign Cert","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/codesigncert.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/resources\/163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/resources"}],"about":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/types\/resources"}],"wp:attachment":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/media?parent=163"}],"wp:term":[{"taxonomy":"resources_category","embeddable":true,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/resources_category?post=163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}