Preventing executables with invalid Authenticode signatures from running
问题 We publish an update patch to our software package in a single executable file. The file is signed with an Authenticode digital signature, using the certificate issued to us. The file is downloaded to Windows XP or Vista systems that our customers operate, where they run it in order to update our software. Our PCI compliance auditor has asked us to protect against the following situation: After downloading our executable file, a malicious person alters the file. An observant person would be