homepage Welcome to WebmasterWorld Guest from 54.166.108.167
register, free tools, login, search, pro membership, help, library, announcements, recent posts, open posts,
Become a Pro Member
Home / Forums Index / WebmasterWorld / Webmaster General
Forum Library, Charter, Moderators: phranque

Webmaster General Forum

    
Thawte/Verisign Software Download Certificate
murmy




msg:3878920
 12:41 am on Mar 26, 2009 (gmt 0)
Im considering purchasing the Thawte digital certificate (authenticode) for a downloadable game client application but we have a technical question we have been unable to find an answer to (even by speaking to Thawte themselves).

The basic issue is that we are eventually going to have affiliates who can refer traffic for revenue share.

The way it works is that when a user (who is referred by an affiliate) downloads the client, the server puts the affiliate ID into the game launcher (setup.exe).

So when a user then installs the client and then registers to become player, the client uses affiliate ID for the registration step (ie to ensure that the affiliate gets the credit for the referral).

Therefore, the server changes (or patches) the game launcher (setup.exe) with an affiliate ID.

My coder has told me that because of this we cannot sign the launcher because each time it is patched the certificate will become invalid.

Have any of you had this problem? Is this correct? If so, is there a way we can get around this problem?

 

kaled




msg:3879543
 6:56 pm on Mar 26, 2009 (gmt 0)

That is almost correct. Unfortunately, there is not an area in the signature code that can be customised and then read back later. This would have been easy to implement but I guess nobody thought to do so.

Your only option is to sign one copy for each affiliate. When a new version is released, you'll either have to delete all the signed copies and arrange for new signed copies to be created on demand or you'll have to create a new set of signed copies.

The signing process is very quick unless you need to include a timestamp (recommended). In this case it may take a few seconds to connect to a timestamp server.

I would recommend creating new signed copies on demand if you running on a Windows server, but if you are running on something else this might be tricky.

Kaled.

Global Options:
 top home search open messages active posts  
 

Home / Forums Index / WebmasterWorld / Webmaster General
rss feed

All trademarks and copyrights held by respective owners. Member comments are owned by the poster.
Home ¦ Free Tools ¦ Terms of Service ¦ Privacy Policy ¦ Report Problem ¦ About ¦ Library ¦ Newsletter
WebmasterWorld is a Developer Shed Community owned by Jim Boykin.
© Webmaster World 1996-2014 all rights reserved