<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Buying a Microsoft code-signing certificate from Thawte? Don&#8217;t use Vista.</title>
	<atom:link href="http://www.itwriting.com/blog/597-buying-a-microsoft-code-signing-certificate-from-thawte-dont-use-vista.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.itwriting.com/blog/597-buying-a-microsoft-code-signing-certificate-from-thawte-dont-use-vista.html</link>
	<description>Tech writing blog</description>
	<lastBuildDate>Sun, 12 Feb 2012 21:04:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Soeren</title>
		<link>http://www.itwriting.com/blog/597-buying-a-microsoft-code-signing-certificate-from-thawte-dont-use-vista.html/comment-page-1#comment-212207</link>
		<dc:creator>Soeren</dc:creator>
		<pubDate>Thu, 08 Jul 2010 12:03:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=597#comment-212207</guid>
		<description>You can use Jailbreak (https://www.isecpartners.com/jailbreak.html) for exporting certificates marked as non-exportable from the Windows certificate store.</description>
		<content:encoded><![CDATA[<p>You can use Jailbreak (<a href="https://www.isecpartners.com/jailbreak.html" rel="nofollow">https://www.isecpartners.com/jailbreak.html</a>) for exporting certificates marked as non-exportable from the Windows certificate store.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David 'dex' Schwartz</title>
		<link>http://www.itwriting.com/blog/597-buying-a-microsoft-code-signing-certificate-from-thawte-dont-use-vista.html/comment-page-1#comment-210113</link>
		<dc:creator>David 'dex' Schwartz</dc:creator>
		<pubDate>Fri, 02 Jul 2010 04:56:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=597#comment-210113</guid>
		<description>The new terminology on the Thawte certificate center web page(s) is &quot;Revoke and Replace&quot;

This page
&lt;a href=&quot;https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;id=SO5559&quot; rel=&quot;nofollow&quot;&gt;Download and Install Microsoft® Authenticode® (Multi-Purpose) Certificate requested with IE7 on Vista/Windows 7&lt;/a&gt;
contains the following note

Please Note: The certificate and key are installed to the browser with the key marked as &quot;Not Exportable&quot;. This means you cannot move your certificate or key to another machine, although you can still sign as per normal from the same system you enrolled from. If a .pfx file is needed, the certificate will need to be replaced with a windows xp machine. Replacement details: &lt;a href=&quot;https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;actp=CROSSLINK&amp;id=SO942&quot; rel=&quot;nofollow&quot;&gt;SO942&lt;/a&gt;

To replace a Code Signing Certificate follow the instructions below:

Read the conditions for a replacement at the following link: &lt;a href=&quot;https://search.thawte.com/support/ssl-digital-certificates/index?page=content&amp;id=so750&quot; rel=&quot;nofollow&quot;&gt;SO750&lt;/a&gt;

Doing the recommended steps on a Windows XP machine allowed the download of the .pvk file and generation of a new certificate.</description>
		<content:encoded><![CDATA[<p>The new terminology on the Thawte certificate center web page(s) is &#8220;Revoke and Replace&#8221;</p>
<p>This page<br />
<a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&#038;id=SO5559" rel="nofollow">Download and Install Microsoft® Authenticode® (Multi-Purpose) Certificate requested with IE7 on Vista/Windows 7</a><br />
contains the following note</p>
<p>Please Note: The certificate and key are installed to the browser with the key marked as &#8220;Not Exportable&#8221;. This means you cannot move your certificate or key to another machine, although you can still sign as per normal from the same system you enrolled from. If a .pfx file is needed, the certificate will need to be replaced with a windows xp machine. Replacement details: <a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&#038;actp=CROSSLINK&#038;id=SO942" rel="nofollow">SO942</a></p>
<p>To replace a Code Signing Certificate follow the instructions below:</p>
<p>Read the conditions for a replacement at the following link: <a href="https://search.thawte.com/support/ssl-digital-certificates/index?page=content&#038;id=so750" rel="nofollow">SO750</a></p>
<p>Doing the recommended steps on a Windows XP machine allowed the download of the .pvk file and generation of a new certificate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry Johnston</title>
		<link>http://www.itwriting.com/blog/597-buying-a-microsoft-code-signing-certificate-from-thawte-dont-use-vista.html/comment-page-1#comment-181611</link>
		<dc:creator>Harry Johnston</dc:creator>
		<pubDate>Sun, 11 Apr 2010 22:49:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=597#comment-181611</guid>
		<description>I&#039;m not absolutely certain, but I have a strong suspicion that Microsoft did not design Internet Explorer&#039;s certificate-generating functionality to be used in this way.

You shouldn&#039;t be generating a code-signing certificate from an on-line machine anyway.  To keep the key safe, it should be generated, stored and used only on isolated machines, i.e., with no network connection.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not absolutely certain, but I have a strong suspicion that Microsoft did not design Internet Explorer&#8217;s certificate-generating functionality to be used in this way.</p>
<p>You shouldn&#8217;t be generating a code-signing certificate from an on-line machine anyway.  To keep the key safe, it should be generated, stored and used only on isolated machines, i.e., with no network connection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Damien</title>
		<link>http://www.itwriting.com/blog/597-buying-a-microsoft-code-signing-certificate-from-thawte-dont-use-vista.html/comment-page-1#comment-138270</link>
		<dc:creator>Damien</dc:creator>
		<pubDate>Wed, 22 Jul 2009 15:07:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=597#comment-138270</guid>
		<description>I currently work for Thawte Technical Support and one of our customers refered me to the article, it is very well written, the only point I had an issue with was the revokation/reissue process for the certificate.

The certificate needs to be reissued, not revoked, when you reissue from www.thawte.com/reissue using Windows XP you will be assigned a new pvk (private key) and order id, then the new certificate is issued and the previous order is revoked as part of the reissue process.

If you just revoke the certificate they will no no longer be able to reissue and the customer would need to place a new order instead of just reissuing which is free.

Damien
Thawte Tech Support</description>
		<content:encoded><![CDATA[<p>I currently work for Thawte Technical Support and one of our customers refered me to the article, it is very well written, the only point I had an issue with was the revokation/reissue process for the certificate.</p>
<p>The certificate needs to be reissued, not revoked, when you reissue from <a href="http://www.thawte.com/reissue" rel="nofollow">http://www.thawte.com/reissue</a> using Windows XP you will be assigned a new pvk (private key) and order id, then the new certificate is issued and the previous order is revoked as part of the reissue process.</p>
<p>If you just revoke the certificate they will no no longer be able to reissue and the customer would need to place a new order instead of just reissuing which is free.</p>
<p>Damien<br />
Thawte Tech Support</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://www.itwriting.com/blog/597-buying-a-microsoft-code-signing-certificate-from-thawte-dont-use-vista.html/comment-page-1#comment-137475</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Sat, 11 Jul 2009 01:11:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/?p=597#comment-137475</guid>
		<description>Thanks for the posting! i spent a few days on this issue &amp; now need to get a XP machine.

This whole issue seems complete lunacy... someone from Microsoft should have go to jail for imposing such restriction!</description>
		<content:encoded><![CDATA[<p>Thanks for the posting! i spent a few days on this issue &amp; now need to get a XP machine.</p>
<p>This whole issue seems complete lunacy&#8230; someone from Microsoft should have go to jail for imposing such restriction!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

