Code signing

Code signing policy

How the Windows releases of the OrbitSSH desktop client are built and signed, who approves a signature, and what happens if something goes wrong.

Status

OrbitSSH is applying to the SignPath Foundation open-source program. Once the application is approved, covered Windows release artifacts will use free code signing provided by SignPath.io, certificate by SignPath Foundation.

Until then, Windows installers are not Authenticode-signed and Windows SmartScreen may warn about an unknown publisher. We will not describe a release as signed before it actually is.

What gets signed

Source and build provenance

Automatic updates

In addition to Authenticode, every installer delivered through the in-app updater carries a separate update signature. The client refuses any update whose signature does not match the public key built into it. The private key for update signatures is kept by the maintainer offline and is never uploaded to GitHub or any build service.

Roles

OrbitSSH is currently maintained by an individual maintainer.

Contributions from other people are accepted through pull requests and are reviewed before merging.

Key protection and revocation

OrbitSSH maintainers never receive or store the SignPath Foundation private key. Signing is performed by SignPath.io under the approved project and signing policies.

If a signed artifact, the release workflow, a maintainer account or a signing request is suspected to be compromised, we stop signing and publishing, investigate, notify SignPath Foundation and request revocation where appropriate.

Privacy

See the OrbitSSH privacy policy.

Back to home