Authenticode signing certificate empty subject DN

ID PE185 Level ERROR Category Format

Description

Authenticode signing certificate subject distinguished name is empty. Signing certificate which does not specify the subject is not valid.

Mitigation

  • When generating the CSR (certificate signing request) using openssl req, do not omit the answers to the openssl prompts.
  • Alternatively, specify the distinguished name details in the configuration file. See the openssl req documentation page for more details.

Arguments

This rule has the following output arguments:

  • signature_info - Readable affected signature name (e.g. "root signature", "timestamp root signature", "nested signature (index 1)")