Our binaries are timestamped, and we expect them to be deemed
valid by Windows even after the certificate expires. And they
are.
However, our own code explicitly passes WTD_LIFETIME_SIGNING
to the WinTrust APIs, overriding Windows's default of treating
timestamped binaries as valid even after certificate expiry.
(As long as the certificate doesn't have the lifetime signing bit
set!)
From Windows Authenticode Portable Executable Signature Format [1]:
> Timestamp Processing with Lifetime Signing Semantics
>
> Applications or certification authorities that do not want timestamped
> signatures to verify successfully for an indefinite period of time have
> two options:
>
> - Set the lifetime signer OID in the publishers signing certificate.
>
> If the publishers signing certificate contains the lifetime signer
> OID in addition to the PKIX code signing OID, the signature becomes
> invalid when the publishers signing certificate expires, even if
> the signature is timestamped. The lifetime signer OID is defined as
> follows:
>
> szOID_KP_LIFETIME_SIGNING 1.3.6.1.4.1.311.10.3.13
>
> - Set the WTD_LIFETIME_SIGNING_FLAG in the WINTRUST_DATA structure
> when calling WinVerifyTrust.
>
> If a WinVerifyTrust caller sets WTD_LIFETIME_SIGNING_FLAG in the
> WINTRUST_DATA structure and the publishers signing certificate has
> expired, WinVerifyTrust reports the signature as invalid even if the
> signature is timestamped.
>
> If a publisher revokes a code signing certificate that contains the lifetime
> signer OID or a WinVerifyTrust caller sets WTD_LIFETIME_SIGNING_FLAG in the
> WINTRUST_DATA structure, WinVerifyTrust reports the signature as valid if both
> of the following conditions are met:
>
> - The signature was timestamped before the revocation date.
> - The signing certificate is still withinits validity period. After the
> validity period expires, the signature becomes invalid.
[1]: Windows Authenticode Portable Executable Signature Format
Version 1.0 March 21, 2008
http://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/Authenticode_PE.docx
|
||
|---|---|---|
| .tx | ||
| 3rdparty | ||
| 3rdPartyLicenses | ||
| g15helper | ||
| icons | ||
| installer | ||
| macx | ||
| man | ||
| overlay | ||
| overlay_gl | ||
| overlay_winx64 | ||
| plugins | ||
| samples | ||
| scripts | ||
| src | ||
| themes | ||
| toolchain/win32-msvc2013 | ||
| .gitignore | ||
| .gitmodules | ||
| .mailmap | ||
| AUTHORS | ||
| CHANGES | ||
| compiler.pri | ||
| Doxyfile | ||
| INSTALL | ||
| LICENSE | ||
| LICENSE.header | ||
| main.pro | ||
| python.pri | ||
| qt.pri | ||
| rcc.pri | ||
| README | ||
| README.Linux | ||
| README.md | ||
| README.static.linux | ||
| README.static.osx | ||
| symbols.pri | ||
| winpaths_default.pri | ||
| winpaths_static.pri | ||
Mumble - A voicechat utility for gamers
http://mumble.info/
#mumble on freenode
Mumble is a voicechat program for gamers written on top of Qt and Speex.
There are two modules in Mumble; the client (mumble) and the server (murmur). The client works on Win32/64, Linux and Mac OS X, while the server should work on anything Qt can be installed on.
Note that when we say Win32, we mean Windows XP or newer.
Running Mumble
On Windows, after installation, you should have a new Mumble folder in your Start Menu, from which you can start Mumble.
On Mac OS X, to install Mumble, drag the application from the downloaded
disk image into your /Applications folder.
Once Mumble is launched, you need a server to connect to. Either create your own or join a friend's.
Running Murmur on Unix-like systems
Murmur should be run from the command line, so start a shell (command prompt) and go to wherever you installed Mumble. Run murmur as
murmurd [-supw <password>] [-ini <inifile>] [-fg] [v]
-supw Set new password for the user SuperUser, which is hardcoded to
bypass ACLs. Keep this password safe. Until you set a password,
the SuperUser is disabled. If you use this option, murmur will
set the password in the database and then exit.
-ini Use a inifile other than murmur.ini, use this to run several instances
of murmur from the same directory. Make sure each instance is using
a separate database.
-fg Run in the foreground, logging to standard output.
-v More verbose logging.
Running Murmur on Mac OS X
Murmur is distributed seperately from the Mumble client on Mac OS X. It is called Static OS X Server and can be downloaded from the main webpage.
Once downloaded it can be run in the same way as on any other Unix-like system. For more information please see the 'Running Murmur on Unix-like systems' above.
Running Murmur on Win32
Doubleclick the Murmur icon to start murmur. There will be a small icon on your taskbar from which you can view the log.
To set the superuser password, run murmur with the parameters -supw <password>.
Bandwidth usage
Mumble will use 10-40 kbit/s outgoing, and the same incoming for each user. So if there are 10 other users on the server with you, your incoming bandwidth requirement will be 100-400 kbit/s if they all talk at the same time.