Skip to content

scripts: fix compute_authenticode_hash for unsigned PEs - #440

Merged
Doug Flick (Flickdm) merged 1 commit into
microsoft:mainfrom
jeremy-compostella:jcompost/fix-compute_authenticode_hash-for-unsigned-PEs
Jul 6, 2026
Merged

Doug Flick (Flickdm) merged 1 commit into
microsoft:mainfrom
jeremy-compostella:jcompost/fix-compute_authenticode_hash-for-unsigned-PEs

Conversation

@jeremy-compostella

@jeremy-compostella Jérémy Compostella (jeremy-compostella) commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

When the PE has no attached certificate the security data directory fields VirtualAddress and Size are both 0. The previous unconditional slicing:

pe_data[certificate_table_offset + 0x08 : 0]   # -> empty
+ pe_data[0 + 0 :]                              # -> whole file re-appended

produced a wrong digest for unsigned images.

Add an explicit branch: when VirtualAddress == 0, hash only the bytes that follow the 8-byte cert-dir data-directory entry, which is the correct tail of an unsigned PE image.

Description

When the PE has no attached certificate the security data directory
fields VirtualAddress and Size are both 0. The previous unconditional
slicing:

pe_data[certificate_table_offset + 0x08 : 0]   # -> empty
+ pe_data[0 + 0 :]                              # -> whole file re-appended

produced a wrong digest for unsigned images.

How This Was Tested

Generate Authenticode for an unsigned EFI binary and verify successful verification once enrolled in the DB.

Integration Instructions

N/A

@jeremy-compostella
Jérémy Compostella (jeremy-compostella) force-pushed the jcompost/fix-compute_authenticode_hash-for-unsigned-PEs branch 2 times, most recently from fcbcb75 to 7737602 Compare June 23, 2026 18:17
@Flickdm
Doug Flick (Flickdm) force-pushed the jcompost/fix-compute_authenticode_hash-for-unsigned-PEs branch 2 times, most recently from 1b44710 to 6858195 Compare July 1, 2026 17:57
When the PE has no attached certificate the security data directory
fields VirtualAddress and Size are both 0.  The previous unconditional
slicing:

    pe_data[certificate_table_offset + 0x08 : 0]   # -> empty
    + pe_data[0 + 0 :]                              # -> whole file re-appended

produced a wrong digest for unsigned images.

Add an explicit branch: when VirtualAddress == 0, hash only the bytes
that follow the 8-byte cert-dir data-directory entry, which is the
correct tail of an unsigned PE image.

Signed-off-by: Jeremy Compostella <jeremy.compostella@intel.com>
@jeremy-compostella
Jérémy Compostella (jeremy-compostella) force-pushed the jcompost/fix-compute_authenticode_hash-for-unsigned-PEs branch from 6858195 to b558383 Compare July 3, 2026 13:35
@Flickdm
Doug Flick (Flickdm) merged commit 798cdc5 into microsoft:main Jul 6, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants