Skip to content

Rule 10003

Kevin Jones edited this page Apr 12, 2016 · 1 revision

Rule 10003 - Timestamped Rule

This rule checks that each signature contains a timestamp countersign. Both Authenticode and RFC3161 timestamps are handled.

If a signature is missing a timestamp, the rule fails. If the digest algorithm of the timestamp's signature is not equal to the digest algorithm of the signature, the rule fails.

Clone this wiki locally