<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGISSignAddIn.exe receives &amp;quot;internal consistency check failed&amp;quot; when using a KSP-based certificate in ArcGIS Pro SDK Questions</title>
    <link>https://community.esri.com/t5/arcgis-pro-sdk-questions/arcgissignaddin-exe-receives-quot-internal/m-p/1357400#M10808</link>
    <description>&lt;P&gt;Have you had any success with getting an AddInX signed using a KSP? My Digicert certificate expired and now I'm left with the choice of going with a hardware token or cloud storage. I can't find any documentation stating if either one works using the ArcGISSignAddIn.exe tool.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2023 15:41:02 GMT</pubDate>
    <dc:creator>sgn_GSI</dc:creator>
    <dc:date>2023-12-06T15:41:02Z</dc:date>
    <item>
      <title>ArcGISSignAddIn.exe receives "internal consistency check failed" when using a KSP-based certificate</title>
      <link>https://community.esri.com/t5/arcgis-pro-sdk-questions/arcgissignaddin-exe-receives-quot-internal/m-p/1330864#M10433</link>
      <description>&lt;P&gt;We've been digitally signing an ArcGIS Pro add-in using the using the &lt;EM&gt;ArcGISSignAddIn.exe&lt;/EM&gt; tool (per &lt;A href="https://github.com/Esri/arcgis-pro-sdk/wiki/ProGuide-Digitally-signed-add-ins-and-configurations#applying-digital-signatures-to-an-add-in" target="_blank"&gt;https://github.com/Esri/arcgis-pro-sdk/wiki/ProGuide-Digitally-signed-add-ins-and-configurations#applying-digital-signatures-to-an-add-in&lt;/A&gt;).&amp;nbsp; To date, we've been using the tool with a .pfx certificate file.&lt;/P&gt;&lt;P&gt;The world has changed.&amp;nbsp; Beginning on June 1 of this year, per the latest &lt;A href="https://cabforum.org/wp-content/uploads/EV-Code-Signing-v.1.4.pdf" target="_self"&gt;standard&lt;/A&gt;, &lt;EM&gt;private keys for code signing certificates must be stored on hardware certified as FIPS 140-2 level 2, Common Criteria EAL 4+, or equivalent&lt;/EM&gt;.&amp;nbsp; For our use case, we elected to use a cloud-based Key Storage Provider (KSP) for this (i.e., &lt;A href="https://knowledge.digicert.com/solution/digicert-keylocker.html" target="_self"&gt;DigiCert KeyLocker&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;This new approach has worked well with conventional Microsoft &lt;EM&gt;signtool.exe&lt;/EM&gt; based signing, but it's unfortunately &lt;U&gt;not&lt;/U&gt; working with &lt;EM&gt;ArcGISSignAddin.exe&lt;/EM&gt;.&amp;nbsp; When attempting to use the tool with the new KSP-based certificate (as available via the certificate store), an "Internal consistency check failed" error is received and the add-in is not signed.&lt;/P&gt;&lt;P&gt;Any suggestions?&amp;nbsp; Is anyone successfully using &lt;EM&gt;ArcGISSignAddIn.exe&lt;/EM&gt; with a Key Storage Provider?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 21:53:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-sdk-questions/arcgissignaddin-exe-receives-quot-internal/m-p/1330864#M10433</guid>
      <dc:creator>Brent_Davis</dc:creator>
      <dc:date>2023-09-20T21:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGISSignAddIn.exe receives "internal consistency check failed" when using a KSP-based certificate</title>
      <link>https://community.esri.com/t5/arcgis-pro-sdk-questions/arcgissignaddin-exe-receives-quot-internal/m-p/1357400#M10808</link>
      <description>&lt;P&gt;Have you had any success with getting an AddInX signed using a KSP? My Digicert certificate expired and now I'm left with the choice of going with a hardware token or cloud storage. I can't find any documentation stating if either one works using the ArcGISSignAddIn.exe tool.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 15:41:02 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-sdk-questions/arcgissignaddin-exe-receives-quot-internal/m-p/1357400#M10808</guid>
      <dc:creator>sgn_GSI</dc:creator>
      <dc:date>2023-12-06T15:41:02Z</dc:date>
    </item>
  </channel>
</rss>

