Colin Cogle :verified:<p>Help, I need a code signing certificate that won't bankrupt me.</p><p>Three years ago, I paid $100 for a three-year code signing certificate. I've signed all my open-source projects' releases with it. Now that it's renewal time, Certera (SignMyCode.com) wants almost $700 for the same three-year certificate (excluding the mandatory HSM purchase, which I am totally on board with).</p><p>I write silly C and PowerShell code, and I timestamp my signatures so that they're perpetually valid. My PowerShell Gallery stuff, as well as binaries of aprs-weather-submit on Windows and macOS, are all signed and hashed (but not notarized by Apple, because that's another $99 a year for something that feels done unless Bob Bruninga's followers are thinking about APRS 2.0).</p><p>If I can't find a solution, anything I write or update in the future will have to be released as unsigned unless I half-ass something (like the Notepad++ developer using self-signed certs -- semi-dangerously clever). $100 every three years, fine. $700 every three years, and I'll do it if my three fans click my Buy Me A Coffee link over and over.</p><p>Is there any CA out there that will offer open-source, not-for-profit developers like me a chance to get globally-trusted code signing certificates? I don't think SigStore ever took off (sadly), and even if it did, I don't think it's part of the Microsoft Authenticode program.</p><p><a href="https://mastodon.colincogle.name/tags/CodeSigning" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CodeSigning</span></a> <a href="https://mastodon.colincogle.name/tags/SSL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSL</span></a> <a href="https://mastodon.colincogle.name/tags/TLS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLS</span></a> <a href="https://mastodon.colincogle.name/tags/certificates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>certificates</span></a> <a href="https://mastodon.colincogle.name/tags/Certera" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Certera</span></a> <a href="https://mastodon.colincogle.name/tags/SoftwareDevelopment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareDevelopment</span></a> <a href="https://mastodon.colincogle.name/tags/C" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>C</span></a> <a href="https://mastodon.colincogle.name/tags/PowerShell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerShell</span></a> <a href="https://mastodon.colincogle.name/tags/PowerShellGallery" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PowerShellGallery</span></a> <a href="https://mastodon.colincogle.name/tags/AmateurRadio" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AmateurRadio</span></a> <a href="https://mastodon.colincogle.name/tags/HamRadio" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HamRadio</span></a> <a href="https://mastodon.colincogle.name/tags/APRS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>APRS</span></a> <a href="https://mastodon.colincogle.name/tags/APRS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>APRS</span></a>-Weather-Submit <a href="https://mastodon.colincogle.name/tags/GitHub" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GitHub</span></a> <a href="https://mastodon.colincogle.name/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.colincogle.name/tags/developer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>developer</span></a> <a href="https://mastodon.colincogle.name/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://mastodon.colincogle.name/tags/macOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>macOS</span></a> <a href="https://mastodon.colincogle.name/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.colincogle.name/tags/Authenticode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authenticode</span></a> <a href="https://mastodon.colincogle.name/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevSecOps</span></a> <a href="https://mastodon.colincogle.name/tags/DevOps" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DevOps</span></a></p>