Signature

Code signing

Native tools don't cross the border: signtool exists only on Windows, codesign and spctl only on macOS. The Code signing module reads the bytes and verifies the signatures of executables and installers in both directions: who signed, whether the file was modified, with which timestamp.

What it does

What the Code signing module does

Authenticode (PE)

For .exe, .dll and .sys the Authenticode hash is recomputed excluding what the specification excludes, then signer, chain and countersignature timestamp. Dual signatures (SHA-1 plus nested SHA-256) are both verified.

MSI installers

Signature in the installer container, signer, chain and timestamp.

Mach-O and universal binaries

CodeDirectory (identifier, Team ID, cdhash, flags) and recomputed page hashes. A universal binary has one signature per architecture: Probatio verifies all of them and takes the worst verdict.

DMG and notarisation

Image signature, content integrity and the notarisation ticket stapled with stapler: “is this DMG notarised?” gets an answer even from Windows, offline.

Timestamps and revocation

RFC 3161 timestamps and OCSP revocation with the same verification engine used for CAdES and PAdES signatures.

PDF report

Verification record (when the check was made, not when it is printed), hash of the examined file, signatures one by one, chain, findings and scope of the check.

Step by step

How it works

  1. Drop an .exe, a .dll, an .msi, a Mac binary or a .dmg: the format is recognised from its bytes.
  2. Read the outcome of each signature: integrity, signer, chain, timestamp, ticket.
  3. Generate the PDF report.
FAQ

Frequently asked questions

Can I verify an .exe's signature without Windows?
Yes. Probatio recomputes the Authenticode hash and verifies signer, chain and timestamp by reading the file's bytes: it doesn't use signtool.
How do I know whether a DMG is notarised, from Windows?
The notarisation ticket stapled with stapler lives inside the image's signature: Probatio reads it without spctl and offline. It checks that it is there; it doesn't ask Apple about its validity today.
Is the verdict the same as Windows' or Gatekeeper's?
Not necessarily: operating systems consult their own certificate programmes and, for Apple, their own servers. Probatio shows the chain and says whether it reaches a root it knows (the AgID/EU trust list); for code signatures it usually doesn't, and it says so.