Allowing unattended installation of unsigned drivers ...

I worked/am working for 2 companies that produce mass
amount of graphics/network silicon for PC running
NTOS. In these companies, WHQL cert. test is just one
of many tests drivers have to pass before release.

At ATI, A WHQL test among other acceptance unit tests
are automatically kicked off on Radeon Graphics Driver
nightly builds(staging builds, branch builds, dot
release builds, OEM builds etc). Developer whose
checkin(s) broke the nightly automated tests will
receive an ugly broadcast email CC’d to a huge list of
people, managers. and all checkins of the day (from
all developers) to that specific staging build are
marked as “not promotable (to mainline build)”. The
guy who screwed up is likely assgined a showstopper
and s/he probably wants to fix it before the nightly
test fires again. QA team won’t even bother start our
own test plan on the driver until it’s fixed.

At brcm, we don’t expect NdisTest to catch any bug in
our driver, frankly.

My point is that a driver couldn’t even pass
applicable WQHL cert. must have some serious
problem(s).

Calvin Guan (Windows DDK MVP)
Staff SW Engineer, NetXtreme MINIPORT
Broadcom Corp. Irvine, CA
www.broadcom.com

— Mark Roddy wrote:

> If a company has built quality control into their
> product then the WHQL test
> ought to be trivial. My completely subjective
> experience is that, in
> general, the lack of a signed driver correlates with
> shitty quality.
>
> Like I said originally, WHQL doesn’t guarantee
> quality, but lack of WHQL
> qualification seems to correlate with lack of
> quality.
>
> =====================
> Mark Roddy DDK MVP
> Windows 2003/XP/2000 Consulting
> Hollis Technology Solutions 603-321-1032
> www.hollistech.com
>
> > -----Original Message-----
> > From: xxxxx@lists.osr.com
> > [mailto:xxxxx@lists.osr.com] On
> Behalf Of Don Burn
> > Sent: Monday, July 04, 2005 12:42 PM
> > To: Windows System Software Devs Interest List
> > Subject: Re: Re:[ntdev] Allowing unattended
> installation of
> > unsigned drivers …
> >
> > Yeah, at $200 a pop this is a huge revenue stream.
> I’ve
> > encountered a few companies that claim their
> quality control
> > is outstanding and Microsoft testing is worthless
> or wrong.
> > Seems like any driver I get from them is crap,
> with memory
> > leaks and other stupidities.
> >
> > The claim of that it takes a lot of time and
> effort causing
> > missed windows is stupid also. Yes there are
> cases where if
> > something is unique you will get nailed because of
> the tests.
> > But most devices if they work propoerly should
> pass the
> > testing relatively easily and after the first
> submission this
> > is a no brainer. Microsoft has gotten their
> turnaround for
> > submissions down to a day or two so this is not
> going to miss
> > a marketing window.
> >
> > Don Burn (MVP, Windows DDK)
> > Windows 2k/XP/2k3 Filesystem and Driver Consulting
> Remove
> > StopSpam from the email to reply
> >
> >
> >
> > ----- Original Message -----
> > From: “BobF”
> > Newsgroups: ntdev
> > To: “Windows System Software Devs Interest List”
>
> > Sent: Monday, July 04, 2005 10:59 AM
> > Subject: Re:[ntdev] Allowing unattended
> installation of
> > unsigned drivers …
> >
> >
> > > On Mon, 4 Jul 2005 10:35:51 -0400, Mark Roddy
> wrote:
> > >
> > >> Everytime I install hardware and the driver is
> unsigned I
> > think ‘here is
> > >> a
> > >> comapny that cannot even be bothered to get
> their drivers signed’.
> > >> Signing
> > >> is no guarantee of quality, but lack of a
> signature is a
> > pretty good
> > >> indicator of a company that just doesn’t care
> much about quality.
> > >>
> > > … or of a company that has built quality
> control into their own
> > > infrastructure instead of supporting this
> particular M$
> > revenue stream.
> > >
> > > —
> > > Questions? First check the Kernel Driver FAQ at
> > > http://www.osronline.com/article.cfm?id=256
> > >
> > > You are currently subscribed to ntdev as:
> xxxxx@acm.org
> > > To unsubscribe send a blank email to
> xxxxx@lists.osr.com
> > >
> >
> >
> > —
> > Questions? First check the Kernel Driver FAQ at
> > http://www.osronline.com/article.cfm?id=256
> >
> > You are currently subscribed to ntdev as:
> xxxxx@hollistech.com
> > To unsubscribe send a blank email to
> xxxxx@lists.osr.com
> >
>
>
>
> —
> Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as:
> xxxxx@yahoo.ca
> To unsubscribe send a blank email to
> xxxxx@lists.osr.com
>

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

> general, the lack of a signed driver correlates with shitty quality.

Not necessary. Imagine: a company signs the driver, then finds some bugs in it,
and issues the bugfixing release, not bothering to sign the latter. In this
case, we have 2 driver packages - old, signed and bad, and new, unsigned and
good.

This was a reality with nVidia Detonator in around 2000-2001.

Maxim Shatskih, Windows DDK MVP
StorageCraft Corporation
xxxxx@storagecraft.com
http://www.storagecraft.com

SW team at that size must have a lot of bugfixs
everyday, especially for video driver:). I believe NV
internally ran HCT/WHQL test against their driver even
though the package is unsigned. Long time ago, ATI
also put unsigned driver package on their website and
clearly marked “not certified”. I don’t think they are
doing that anymore. These companies usually are
eligible for signing their drivers in-house nowadays.
(A good portion of video cert. test is developed by
ATI.)

Calvin Guan (Windows DDK MVP)
Staff SW Engineer, NetXtreme MINIPORT
Broadcom Corp. Irvine, CA
www.broadcom.com

— “Maxim S. Shatskih”
wrote:

> > general, the lack of a signed driver correlates
> with shitty quality.
>
> Not necessary. Imagine: a company signs the driver,
> then finds some bugs in it,
> and issues the bugfixing release, not bothering to
> sign the latter. In this
> case, we have 2 driver packages - old, signed and
> bad, and new, unsigned and
> good.
>
> This was a reality with nVidia Detonator in around
> 2000-2001.
>
> Maxim Shatskih, Windows DDK MVP
> StorageCraft Corporation
> xxxxx@storagecraft.com
> http://www.storagecraft.com
>
>
> —
> Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as:
> xxxxx@yahoo.ca
> To unsubscribe send a blank email to
> xxxxx@lists.osr.com
>

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

Why did they ‘not bother to sign the latter’? If the newer driver is ‘in
the box’ with the hardware they have no excuse. If this is a download
from their website and constitutes an interim release to address a
serious defect, a hot-fix situation, that is excusable. Presumably a
signed version will be available shortly thereafter.

How exactly do these high quality vendors who can’t be bothered to whql
their drivers get their products onto systems that by policy do not
allow unsigned drivers? They don’t, they just inflict their crappy
drivers on the millions of consumers out there who haven’t a clue.

-----Original Message-----
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Maxim S. Shatskih
Sent: Monday, July 04, 2005 8:15 PM
To: Windows System Software Devs Interest List
Subject: Re: Re:[ntdev] Allowing unattended installation of unsigned
drivers …

general, the lack of a signed driver correlates with shitty quality.

Not necessary. Imagine: a company signs the driver, then finds some bugs
in it,
and issues the bugfixing release, not bothering to sign the latter. In
this
case, we have 2 driver packages - old, signed and bad, and new, unsigned
and
good.

This was a reality with nVidia Detonator in around 2000-2001.

Maxim Shatskih, Windows DDK MVP
StorageCraft Corporation
xxxxx@storagecraft.com
http://www.storagecraft.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: xxxxx@stratus.com
To unsubscribe send a blank email to xxxxx@lists.osr.com

I'm not talking about an Authenticode signature, I'm talking about a
WHQL test signature. They work on any OS that checks signatures.

Of course, you're only allowed to use these for testing purposes, but
one would hope that the OP *isn't* trying to production ship unsigned
drivers that install as though they are signed... right? (hint, hint)

Perhaps that's the point I'm trying to make: *Don't* play games with
driver signing except for testing purposes. If your driver is unsigned,
let it be unsigned.

Anyway, see here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;330315

Actually, most of the information is on pages linked-to by that URL, but
it's a reasonable starting place.

../ray..

Christiaan Ghijselinck wrote:

> Wouldn't it be easier to get a test signature for your driver and
> install the base test certificate on the machines where you want to load
> the driver? It takes almost 0 time to test-sign a driver.
> --
> ../ray..

Yes, but as "Gary" stated "

>>> For Server 2003 drivers you can do this by acquiring an Authenticode
>>> certificate and applying it to your install package. This will not work for
>>> XP however. Check Verisign or other such certificate providers.
>>> --
>>> The personal opinion of
>>> Gary G. Little

.. this works only on Server2003 . Does anyone knows if this will become
available in XP ( SP's ) and become/is available in Longhorn ?

Christiaan

> Christiaan Ghijselinck wrote:
>> Dear all ,
>>
>> Does exists a method or command line tool that allows to turn off ( allow ) the installation of unsigned drivers without the
user
>> prompt , and that subsequently restores the original setting after installation ? Something that suppresses the user prompt
and
>> simulates OK is all right too . I need this rather urgently , and can't wait for the "signation" :slight_smile:
>>
>> Thanks ,
>>
>> Christiaan
>>
>>
>>
> ---
> Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: xxxxx@compaqnet.be
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>

> I’m not talking about an Authenticode signature, I’m talking about a

WHQL test signature. They work on any OS that checks signatures.

Of course, you’re only allowed to use these for testing purposes, but
one would hope that the OP *isn’t* trying to production ship unsigned
drivers that install as though they are signed… right? (hint, hint)

Perhaps that’s the point I’m trying to make: *Don’t* play games with
driver signing except for testing purposes. If your driver is unsigned,
let it be unsigned.

I fully agree ! But assume next scenario :

A driver developer want to provide an OEM version of a signed driver,
branded with some “references” … ( no code changes, resources only ).
He would provide this for , let’s say $50.00 . But it must get signed , so the
seller has to add , from what I have read here : $200.00 , and he has to wait
for how long till WHQL signed ? . Excellent business :frowning:

Christiaan

Anyway, see here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;330315

Actually, most of the information is on pages linked-to by that URL, but
it’s a reasonable starting place.

…/ray..

Christiaan Ghijselinck wrote:
>
>> Wouldn’t it be easier to get a test signature for your driver and
>> install the base test certificate on the machines where you want to load
>> the driver? It takes almost 0 time to test-sign a driver.
>> –
>> …/ray..
>
>
> Yes, but as “Gary” stated "
>
>>>> For Server 2003 drivers you can do this by acquiring an Authenticode
>>>> certificate and applying it to your install package. This will not work for
>>>> XP however. Check Verisign or other such certificate providers.
>>>> –
>>>> The personal opinion of
>>>> Gary G. Little
>
> … this works only on Server2003 . Does anyone knows if this will become
> available in XP ( SP’s ) and become/is available in Longhorn ?
>
>
> Christiaan
>
>
>
>
>
>> Christiaan Ghijselinck wrote:
>>> Dear all ,
>>>
>>> Does exists a method or command line tool that allows to turn off ( allow ) the installation of unsigned drivers without the
> user
>>> prompt , and that subsequently restores the original setting after installation ? Something that suppresses the user prompt
> and
>>> simulates OK is all right too . I need this rather urgently , and can’t wait for the “signation” :slight_smile:
>>>
>>> Thanks ,
>>>
>>> Christiaan
>>>
>>>
>>>
>> —
>> Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256
>>
>> You are currently subscribed to ntdev as: xxxxx@compaqnet.be
>> To unsubscribe send a blank email to xxxxx@lists.osr.com
>>
>
>


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: xxxxx@compaqnet.be
To unsubscribe send a blank email to xxxxx@lists.osr.com

----- Original Message -----
From: “Christiaan Ghijselinck”
> A driver developer want to provide an OEM version of a signed driver,
> branded with some “references” … ( no code changes, resources only ).
> He would provide this for , let’s say $50.00 . But it must get signed , so
> the
> seller has to add , from what I have read here : $200.00 , and he has to
> wait
> for how long till WHQL signed ? . Excellent business :frowning:
>

Well, I don’t remember if you have to do the full $200, though an OEM driver
for $50 is way too low, sorry if you are touching things it is going to be
more than that. As far as the turn around, I know from colleague who have
done this it is less than a working day.

WHQL used to be bad, and yes it can still be a pain if you are doing
something out of the ordinary, but need to pass a standard device category.
But, niost of the claims about WHQL I have seen in this discussion are at
least 4 years out of date.

Don Burn (MVP, Windows DDK)
Windows 2k/XP/2k3 Filesystem and Driver Consulting
Remove StopSpam from the email to reply

Intel (INTEL!) does not seem to bother signing their motherboard chipset drivers at all.

“Mark Roddy” wrote in message news:xxxxx@ntdev…
Everytime I install hardware and the driver is unsigned I think ‘here is a comapny that cannot even be bothered to get their drivers signed’. Signing is no guarantee of quality, but lack of a signature is a pretty good indicator of a company that just doesn’t care much about quality.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

----------------------------------------------------------------------------
From: xxxxx@lists.osr.com [mailto:xxxxx@lists.osr.com] On Behalf Of Alberto Moreira
Sent: Monday, July 04, 2005 10:17 AM
To: Windows System Software Devs Interest List
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers …

Some production software overflows the concept of “signing”. And the requirements for signing are far too encompassing anyway, so, I take the opposite viewpoint: unless I need my software to be signed - emphasis on the need - my attitude is, why bother ? It’s a big drain in manpower, it extends the product cycle by a significant amount and it may cause the product to miss a marketing window.

Alberto.

----- Original Message -----
From: Christiaan Ghijselinck
To: Windows System Software Devs Interest List
Sent: Monday, July 04, 2005 2:54 AM
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers …

If you are trying to “turn off” unsigned driver warnings in order to install some software that doesn’t have a signature across your enterprise, use the domain policy to allow it,

Correct , but the domain policy and the settings within Device Manager for “Signing” are OR-ed . If one sets te Domain Policy to “allow unsigned” , the OS will still prompt if the user left ( or has set ) the default “Prompt” value .

Btw.: On a particular XP system, I get this during normal operation ( setupapi.log ) :

#E360 An unsigned or incorrectly signed file “D:\WINDOWS\system32\xxxxxxx” for driver “xxxxxxxxx” will be installed (Policy=Ignore). Error 0x800b0100: No signature was present in the subject.

And in fact there is NO prompt during installation of the driver , although domain policy and the “Driver Signing Options” accessed via Device Manager are set to “Warn” . Any ideas how to bring this situation back to normal ?

Christiaan

although you might question your vendor about why it’s unsigned, such as there is no WHQL category for that class of driver or something like that.

If you are trying to do this so you can ship your unfinished product, don’t. Finish it right, then ship it.

Phil

Philip D. Barila
Seagate Technology LLC
(720) 684-1842

“Christiaan Ghijselinck”
Sent by: xxxxx@lists.osr.com
No Phone Info Available
07/02/2005 07:34 AM Please respond to
“Windows System Software Devs Interest List”

To “Windows System Software Devs Interest List”
cc
Subject Re: Re:[ntdev] Allowing unattended installation of unsigned drivers …

> Wouldn’t it be easier to get a test signature for your driver and
> install the base test certificate on the machines where you want to load
> the driver? It takes almost 0 time to test-sign a driver.
> –
> …/ray..

Yes, but as “Gary” stated "

>>>For Server 2003 drivers you can do this by acquiring an Authenticode
>>>certificate and applying it to your install package. This will not work for
>>>XP however. Check Verisign or other such certificate providers.
>>>–
>>>The personal opinion of
>>>Gary G. Little

… this works only on Server2003 . Does anyone knows if this will become
available in XP ( SP’s ) and become/is available in Longhorn ?

Christiaan

>
> Christiaan Ghijselinck wrote:
> > Dear all ,
> >
> > Does exists a method or command line tool that allows to turn off ( allow ) the installation of unsigned drivers without the
user
> > prompt , and that subsequently restores the original setting after installation ? Something that suppresses the user prompt
and
> > simulates OK is all right too . I need this rather urgently , and can’t wait for the “signation” :slight_smile:
> >
> > Thanks ,
> >
> > Christiaan
> >
> >
> >
>
> —
> Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: xxxxx@compaqnet.be
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: xxxxx@seagate.com
To unsubscribe send a blank email to xxxxx@lists.osr.com

— Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256 You are currently subscribed to ntdev as: xxxxx@compaqnet.be To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com

>> What it does do, is sign the driver with a certificate that provides a strong degree of certainty that the driver being installed is authentic.

I wish it would be so, then we wouldn’t have had a subject to discuss.

If it was so, then we wouldn’t need to send our drivers to Microsoft. It would be enough to pay $400 p.a. to Verisign, or better, just $99 to any other non-MS-endorsed authority for a digital certificate.


http://www.cristalink.com

“Gary G. Little” wrote in message news:xxxxx@ntdev…
WHQL does not prove quality. WHQL provides no assurance, at all, that the driver you are about to install on your hardware will work in your hardware. It never has and it probably never will. Quality is in the purview of the authoring agency. Therefore, any argument as to quality provided by WHQL is spurious.

What it does do, is sign the driver with a certificate that provides a strong degree of certainty that the driver being installed is authentic. and not the proverbial wolf in sheep’s clothing. At the 2002 and 2003 DevCon I heard over and over again that if software was not signed that software would not be installed. It was not a quality issue, it was a security issue. The certificated package provided proof that the software was authentic. To refuse to provide that proof of authenticity to a customer is, as Don would say, stupid, and as I would say, shows ignorance of what WHQL provides.

Server 2003 and Longhorn will allow an Aurthenticode signature to prove authenticity. I personally think that should be extended to the next service pack for XP and 2000. I certainly don’t mind proving that the package I just delivered really is from me.


The personal opinion of
Gary G. Little
“Alberto Moreira” wrote in message news:xxxxx@ntdev…
Some companies have their own quality mechanisms. Some products do not fit the current signing track. My own experience is that whql is a costly, lengthy, resource-wasting process; if I look back, whql has been a money sink with little or no return. Worse, we had to spend a lot of time, money and energy adding bells and whistles that we wouldn’t have bothered with, just to pass whql and keep some mouths shut. Good Lord, how much time did I waste looking for a 1% difference in one pixel in a large texture map, or bothering to render by software instead of by hardware because there was a half-pixel deviation between my triangle and what they wanted - even though the OpenGL spec itself allowed me the leeway ? Having to coax my chip and my pipeline to render exactly the same as the Microsoft OpenGL implementation ?

Thanks but no, thanks. I pass.

But that said, let me throw in a suggestion. How about a Microsoft-independent way of certifying software quality ? A mechanism that concentrates on real quality ? a design-independent mechanism ? A mechanism that respects established industrywide standards achieved by multilateral agreement ? A mechanism that does not rely on compliance with party-line tenets ? An objective, unbiased mechanism, that establishes clear objectives to be attained with and only with the product’s executable and no other strings attached ? A mechanism established by a wide consensus ? A mechanism that’s portable across platforms and across operating systems ?

Hey, I’d be fully supportive of it.

Alberto.

----- Original Message -----
From: Mark Roddy
To: Windows System Software Devs Interest List
Sent: Monday, July 04, 2005 10:35 AM
Subject: RE: [ntdev] Allowing unattended installation of unsigned drivers …

Everytime I install hardware and the driver is unsigned I think ‘here is a comapny that cannot even be bothered to get their drivers signed’. Signing is no guarantee of quality, but lack of a signature is a pretty good indicator of a company that just doesn’t care much about quality.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

------------------------------------------------------------------------
From: xxxxx@lists.osr.com [mailto:xxxxx@lists.osr.com] On Behalf Of Alberto Moreira
Sent: Monday, July 04, 2005 10:17 AM
To: Windows System Software Devs Interest List
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers …

Some production software overflows the concept of “signing”. And the requirements for signing are far too encompassing anyway, so, I take the opposite viewpoint: unless I need my software to be signed - emphasis on the need - my attitude is, why bother ? It’s a big drain in manpower, it extends the product cycle by a significant amount and it may cause the product to miss a marketing window.

Alberto.

----- Original Message -----
From: Christiaan Ghijselinck
To: Windows System Software Devs Interest List
Sent: Monday, July 04, 2005 2:54 AM
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers …

If you are trying to “turn off” unsigned driver warnings in order to install some software that doesn’t have a signature across your enterprise, use the domain policy to allow it,

Correct , but the domain policy and the settings within Device Manager for “Signing” are OR-ed . If one sets te Domain Policy to “allow unsigned” , the OS will still prompt if the user left ( or has set ) the default “Prompt” value .

Btw.: On a particular XP system, I get this during normal operation ( setupapi.log ) :

#E360 An unsigned or incorrectly signed file “D:\WINDOWS\system32\xxxxxxx” for driver “xxxxxxxxx” will be installed (Policy=Ignore). Error 0x800b0100: No signature was present in the subject.

And in fact there is NO prompt during installation of the driver , although domain policy and the “Driver Signing Options” accessed via Device Manager are set to “Warn” . Any ideas how to bring this situation back to normal ?

Christiaan

although you might question your vendor about why it’s unsigned, such as there is no WHQL category for that class of driver or something like that.

If you are trying to do this so you can ship your unfinished product, don’t. Finish it right, then ship it.

Phil

Philip D. Barila
Seagate Technology LLC
(720) 684-1842

“Christiaan Ghijselinck”
Sent by: xxxxx@lists.osr.com
No Phone Info Available
07/02/2005 07:34 AM Please respond to
“Windows System Software Devs Interest List”

To “Windows System Software Devs Interest List”
cc
Subject Re: Re:[ntdev] Allowing unattended installation of unsigned drivers …

> Wouldn’t it be easier to get a test signature for your driver and
> install the base test certificate on the machines where you want to load
> the driver? It takes almost 0 time to test-sign a driver.
> –
> …/ray..

Yes, but as “Gary” stated "

>>>For Server 2003 drivers you can do this by acquiring an Authenticode
>>>certificate and applying it to your install package. This will not work for
>>>XP however. Check Verisign or other such certificate providers.
>>>–
>>>The personal opinion of
>>>Gary G. Little

… this works only on Server2003 . Does anyone knows if this will become
available in XP ( SP’s ) and become/is available in Longhorn ?

Christiaan

>
> Christiaan Ghijselinck wrote:
> > Dear all ,
> >
> > Does exists a method or command line tool that allows to turn off ( allow ) the installation of unsigned drivers without the
user
> > prompt , and that subsequently restores the original setting after installation ? Something that suppresses the user prompt
and
> > simulates OK is all right too . I need this rather urgently , and can’t wait for the “signation” :slight_smile:
> >
> > Thanks ,
> >
> > Christiaan
> >
> >
> >
>
> —
> Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: xxxxx@compaqnet.be
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: xxxxx@seagate.com
To unsubscribe send a blank email to xxxxx@lists.osr.com

— Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256 You are currently subscribed to ntdev as: xxxxx@compaqnet.be To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com

Hi all

I am new in driver development.I have designed a ndis protocol
driver for a network sniffer product.

every thing is going fine but at the time of installing the driver
my driver is unable to bind or link the adapter.

Is there any problem in installing parocess.
I have created a service which is ndis supported.

Please help me to find out the problem.

Niraj Jha
Pure Thoughts Technology.
New Delhi
India

Surely this depends on the hardware volume and specialisation. What
about drivers for bits of kit that you plug into a PC which quite
clearly are not intended for the consumer market, may be “bleeding
edge”, and are obviously a specialist piece of hardware… ?

MH.


From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Mark Roddy
Sent: 04 July 2005 15:36
To: Windows System Software Devs Interest List
Subject: RE: [ntdev] Allowing unattended installation of unsigned
drivers …

Everytime I install hardware and the driver is unsigned I think ‘here is
a comapny that cannot even be bothered to get their drivers signed’.
Signing is no guarantee of quality, but lack of a signature is a pretty
good indicator of a company that just doesn’t care much about quality.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

This email and any attachments is confidential, may be legally privileged and is intended for the use of the addressee only. If you are not the intended recipient, please note that any use, disclosure, printing or copying of this email is strictly prohibited and may be unlawful. If received in error, please delete this email and any attachments and confirm this to the sender.

Unsigned drivers will be banned in longhorn. Self-signed drivers - as in you
have a verisign signature authority to sign your drivers - are allowed for
some os releases (w2k3 sp1 and xp sp2?) if the driver is not in a whql
class. So there are, and always have been, two elements: authentication (and
I don’t think anyone is making a serious argument that authentication is a
bad thing) and meeting minimal quality standards. We can debate if whql
defines minimal quality standards or not, what we do know is that if your
driver is a signed whql driver then the vendor is authenticated and the
vendor has bothered to pass the whql tests. Like I said originally,
signatures might not mean much, but lack of signatures indicates that the
vendor can’t be bothered and that means something. To me it means that the
driver and the vendor are suspect in terms of quality of product.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com


From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of cristalink
Sent: Sunday, July 17, 2005 10:36 PM
To: Windows System Software Devs Interest List
Subject: Re:[ntdev] Allowing unattended installation of unsigned drivers …

> What it does do, is sign the driver with a certificate that provides a
strong degree of certainty that the driver being installed is authentic.

I wish it would be so, then we wouldn’t have had a subject to discuss.

If it was so, then we wouldn’t need to send our drivers to Microsoft. It
would be enough to pay $400 p.a. to Verisign, or better, just $99 to any
other non-MS-endorsed authority for a digital certificate.


http://www.cristalink.com

“Gary G. Little” wrote in message news:xxxxx@ntdev…
WHQL does not prove quality. WHQL provides no assurance, at all, that the
driver you are about to install on your hardware will work in your hardware.
It never has and it probably never will. Quality is in the purview of the
authoring agency. Therefore, any argument as to quality provided by WHQL is
spurious.

What it does do, is sign the driver with a certificate that provides a
strong degree of certainty that the driver being installed is authentic.
and not the proverbial wolf in sheep’s clothing. At the 2002 and 2003 DevCon
I heard over and over again that if software was not signed that software
would not be installed. It was not a quality issue, it was a security issue.
The certificated package provided proof that the software was authentic. To
refuse to provide that proof of authenticity to a customer is, as Don would
say, stupid, and as I would say, shows ignorance of what WHQL provides.

Server 2003 and Longhorn will allow an Aurthenticode signature to prove
authenticity. I personally think that should be extended to the next service
pack for XP and 2000. I certainly don’t mind proving that the package I just
delivered really is from me.


The personal opinion of
Gary G. Little

“Alberto Moreira” wrote in message news:xxxxx@ntdev…
Some companies have their own quality mechanisms. Some products do not fit
the current signing track. My own experience is that whql is a costly,
lengthy, resource-wasting process; if I look back, whql has been a money
sink with little or no return. Worse, we had to spend a lot of time, money
and energy adding bells and whistles that we wouldn’t have bothered with,
just to pass whql and keep some mouths shut. Good Lord, how much time did I
waste looking for a 1% difference in one pixel in a large texture map, or
bothering to render by software instead of by hardware because there was a
half-pixel deviation between my triangle and what they wanted - even though
the OpenGL spec itself allowed me the leeway ? Having to coax my chip and my
pipeline to render exactly the same as the Microsoft OpenGL implementation ?

Thanks but no, thanks. I pass.

But that said, let me throw in a suggestion. How about a
Microsoft-independent way of certifying software quality ? A mechanism that
concentrates on real quality ? a design-independent mechanism ? A mechanism
that respects established industrywide standards achieved by multilateral
agreement ? A mechanism that does not rely on compliance with party-line
tenets ? An objective, unbiased mechanism, that establishes clear objectives
to be attained with and only with the product’s executable and no other
strings attached ? A mechanism established by a wide consensus ? A mechanism
that’s portable across platforms and across operating systems ?

Hey, I’d be fully supportive of it.

Alberto.

----- Original Message -----
From: Mark mailto:xxxxx Roddy
To: Windows System Software Devs Interest mailto:xxxxx List

Sent: Monday, July 04, 2005 10:35 AM
Subject: RE: [ntdev] Allowing unattended installation of unsigned drivers


Everytime I install hardware and the driver is unsigned I think ‘here is a
comapny that cannot even be bothered to get their drivers signed’. Signing
is no guarantee of quality, but lack of a signature is a pretty good
indicator of a company that just doesn’t care much about quality.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

_____

From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Alberto Moreira
Sent: Monday, July 04, 2005 10:17 AM
To: Windows System Software Devs Interest List
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers


Some production software overflows the concept of “signing”. And the
requirements for signing are far too encompassing anyway, so, I take the
opposite viewpoint: unless I need my software to be signed - emphasis on the
need - my attitude is, why bother ? It’s a big drain in manpower, it
extends the product cycle by a significant amount and it may cause the
product to miss a marketing window.

Alberto.

----- Original Message -----
From: Christiaan mailto:xxxxx Ghijselinck
To: Windows mailto:xxxxx System Software Devs Interest List

Sent: Monday, July 04, 2005 2:54 AM
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers


If you are trying to “turn off” unsigned driver warnings in order to install
some software that doesn’t have a signature across your enterprise, use the
domain policy to allow it,

Correct , but the domain policy and the settings within Device Manager for
“Signing” are OR-ed . If one sets te Domain Policy to “allow unsigned” ,
the OS will still prompt if the user left ( or has set ) the default
“Prompt” value .

Btw.: On a particular XP system, I get this during normal operation (
setupapi.log ) :

#E360 An unsigned or incorrectly signed file “D:\WINDOWS\system32\xxxxxxx”
for driver “xxxxxxxxx” will be installed (Policy=Ignore). Error 0x800b0100:
No signature was present in the subject.

And in fact there is NO prompt during installation of the driver , although
domain policy and the “Driver Signing Options” accessed via Device Manager
are set to “Warn” . Any ideas how to bring this situation back to normal ?

Christiaan

although you might question your vendor about why it’s unsigned, such as
there is no WHQL category for that class of driver or something like that.

If you are trying to do this so you can ship your unfinished product, don’t.
Finish it right, then ship it.

Phil

Philip D. Barila
Seagate Technology LLC
(720) 684-1842

“Christiaan Ghijselinck”
Sent by: xxxxx@lists.osr.com
No Phone Info Available

07/02/2005 07:34 AM

Please respond to
“Windows System Software Devs Interest List”

To
“Windows System Software Devs Interest List”

cc

Subject
Re: Re:[ntdev] Allowing unattended installation of unsigned drivers …

> Wouldn’t it be easier to get a test signature for your driver and
> install the base test certificate on the machines where you want to load
> the driver? It takes almost 0 time to test-sign a driver.
> –
> …/ray..

Yes, but as “Gary” stated "

>>>For Server 2003 drivers you can do this by acquiring an Authenticode
>>>certificate and applying it to your install package. This will not work
for
>>>XP however. Check Verisign or other such certificate providers.
>>>–
>>>The personal opinion of
>>>Gary G. Little

… this works only on Server2003 . Does anyone knows if this will become
available in XP ( SP’s ) and become/is available in Longhorn ?

Christiaan

>
> Christiaan Ghijselinck wrote:
> > Dear all ,
> >
> > Does exists a method or command line tool that allows to turn off (
allow ) the installation of unsigned drivers without the
user
> > prompt , and that subsequently restores the original setting after
installation ? Something that suppresses the user prompt
and
> > simulates OK is all right too . I need this rather urgently , and
can’t wait for the “signation” :slight_smile:
> >
> > Thanks ,
> >
> > Christiaan
> >
> >
> >
>
> —
> Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as:
xxxxx@compaqnet.be
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: xxxxx@seagate.com
To unsubscribe send a blank email to xxxxx@lists.osr.com

— Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256 You are currently subscribed to
ntdev as: xxxxx@compaqnet.be To unsubscribe send a blank
email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com</mailto:xxxxx></mailto:xxxxx></mailto:xxxxx></mailto:xxxxx>

Is this definite - unsigned drivers will not be allowed in Longhorn ? Do
you know if this is documented anywhere ??

Regards

Mark


From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Mark Roddy
Sent: 18 July 2005 11:55
To: Windows System Software Devs Interest List
Subject: RE: [ntdev] Allowing unattended installation of unsigned
drivers …

Unsigned drivers will be banned in longhorn. Self-signed drivers - as in
you have a verisign signature authority to sign your drivers - are
allowed for some os releases (w2k3 sp1 and xp sp2?) if the driver is
not in a whql class. So there are, and always have been, two elements:
authentication (and I don’t think anyone is making a serious argument
that authentication is a bad thing) and meeting minimal quality
standards. We can debate if whql defines minimal quality standards or
not, what we do know is that if your driver is a signed whql driver then
the vendor is authenticated and the vendor has bothered to pass the whql
tests. Like I said originally, signatures might not mean much, but lack
of signatures indicates that the vendor can’t be bothered and that means
something. To me it means that the driver and the vendor are suspect in
terms of quality of product.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

It has been stated in the WinHEC talks on Longhorn for two years. That is
pretty definite to me. Note: there is an ability for an administrator to
sign a driver for use on a machine or a network.


Don Burn (MVP, Windows DDK)
Windows 2k/XP/2k3 Filesystem and Driver Consulting
Remove StopSpam from the email to reply

“Cook, Mark” <mark.cook> wrote in message news:xxxxx@ntdev…
Is this definite - unsigned drivers will not be allowed in Longhorn ? Do
you know if this is documented anywhere ??</mark.cook>

OK thanks Don
The reason I asked is that although I was aware that this may be on the
cards, the last I heard from my company’s representative at Microsoft
(and this was just over a week ago) was that it was too early to make a
decision on this. I’ll have a trawl through the WinHEC discussion notes
to see what I can find.

Regards

Mark

-----Original Message-----
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Don Burn
Sent: 18 July 2005 12:37
To: Windows System Software Devs Interest List
Subject: Re:[ntdev] Allowing unattended installation of unsigned drivers

It has been stated in the WinHEC talks on Longhorn for two years. That
is
pretty definite to me. Note: there is an ability for an administrator
to
sign a driver for use on a machine or a network.


Don Burn (MVP, Windows DDK)
Windows 2k/XP/2k3 Filesystem and Driver Consulting
Remove StopSpam from the email to reply

“Cook, Mark” <mark.cook> wrote in message news:xxxxx@ntdev…
Is this definite - unsigned drivers will not be allowed in Longhorn ? Do
you know if this is documented anywhere ??


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: mark.cook@ca.com
To unsubscribe send a blank email to xxxxx@lists.osr.com</mark.cook>

Yes sure - I am referring to commercial products. I wouldn’t expect, for
example, a USB development kit to contain signed drivers.


From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Martin C Harvey
Sent: Monday, July 18, 2005 6:52 AM
To: Windows System Software Devs Interest List
Subject: RE: [ntdev] Allowing unattended installation of unsigned
drivers …

Surely this depends on the hardware volume and specialisation. What
about drivers for bits of kit that you plug into a PC which quite
clearly are not intended for the consumer market, may be “bleeding
edge”, and are obviously a specialist piece of hardware… ?

MH.


From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Mark Roddy
Sent: 04 July 2005 15:36
To: Windows System Software Devs Interest List
Subject: RE: [ntdev] Allowing unattended installation of unsigned
drivers …

Everytime I install hardware and the driver is unsigned I think ‘here is
a comapny that cannot even be bothered to get their drivers signed’.
Signing is no guarantee of quality, but lack of a signature is a pretty
good indicator of a company that just doesn’t care much about quality.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

This email and any attachments is confidential, may be legally
privileged and is intended for the use of the addressee only. If you are
not the intended recipient, please note that any use, disclosure,
printing or copying of this email is strictly prohibited and may be
unlawful. If received in error, please delete this email and any
attachments and confirm this to the sender.


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument:
‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com

Hmmm…

Of course product definitions are subject to change, but as Don pointed
out this feature of Longhorn has been discussed publicly for two years.
So it would indeed be very surprising if it got defined out of the
release.

-----Original Message-----
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Cook, Mark
Sent: Monday, July 18, 2005 7:45 AM
To: Windows System Software Devs Interest List
Subject: RE: [ntdev] Allowing unattended installation of unsigned
drivers …

OK thanks Don
The reason I asked is that although I was aware that this may be on the
cards, the last I heard from my company’s representative at Microsoft
(and this was just over a week ago) was that it was too early to make a
decision on this. I’ll have a trawl through the WinHEC discussion notes
to see what I can find.

Regards

Mark

-----Original Message-----
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Don Burn
Sent: 18 July 2005 12:37
To: Windows System Software Devs Interest List
Subject: Re:[ntdev] Allowing unattended installation of unsigned drivers

It has been stated in the WinHEC talks on Longhorn for two years. That
is
pretty definite to me. Note: there is an ability for an administrator
to
sign a driver for use on a machine or a network.


Don Burn (MVP, Windows DDK)
Windows 2k/XP/2k3 Filesystem and Driver Consulting
Remove StopSpam from the email to reply

“Cook, Mark” <mark.cook> wrote in message news:xxxxx@ntdev…
Is this definite - unsigned drivers will not be allowed in Longhorn ? Do
you know if this is documented anywhere ??


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: mark.cook@ca.com
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument:
‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com</mark.cook>

Actually maybe Microsoft should get Intel’s signature before they’d be allowed to run their OS on Intel’s hardware ?

Alberto.
----- Original Message -----
From: cristalink
Newsgroups: ntdev
To: Windows System Software Devs Interest List
Sent: Sunday, July 17, 2005 10:23 PM
Subject: Re:[ntdev] Allowing unattended installation of unsigned drivers …

Intel (INTEL!) does not seem to bother signing their motherboard chipset drivers at all.

“Mark Roddy” wrote in message news:xxxxx@ntdev…
Everytime I install hardware and the driver is unsigned I think ‘here is a comapny that cannot even be bothered to get their drivers signed’. Signing is no guarantee of quality, but lack of a signature is a pretty good indicator of a company that just doesn’t care much about quality.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

--------------------------------------------------------------------------
From: xxxxx@lists.osr.com [mailto:xxxxx@lists.osr.com] On Behalf Of Alberto Moreira
Sent: Monday, July 04, 2005 10:17 AM
To: Windows System Software Devs Interest List
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers …

Some production software overflows the concept of “signing”. And the requirements for signing are far too encompassing anyway, so, I take the opposite viewpoint: unless I need my software to be signed - emphasis on the need - my attitude is, why bother ? It’s a big drain in manpower, it extends the product cycle by a significant amount and it may cause the product to miss a marketing window.

Alberto.

----- Original Message -----
From: Christiaan Ghijselinck
To: Windows System Software Devs Interest List
Sent: Monday, July 04, 2005 2:54 AM
Subject: Re: [ntdev] Allowing unattended installation of unsigned drivers …

If you are trying to “turn off” unsigned driver warnings in order to install some software that doesn’t have a signature across your enterprise, use the domain policy to allow it,

Correct , but the domain policy and the settings within Device Manager for “Signing” are OR-ed . If one sets te Domain Policy to “allow unsigned” , the OS will still prompt if the user left ( or has set ) the default “Prompt” value .

Btw.: On a particular XP system, I get this during normal operation ( setupapi.log ) :

#E360 An unsigned or incorrectly signed file “D:\WINDOWS\system32\xxxxxxx” for driver “xxxxxxxxx” will be installed (Policy=Ignore). Error 0x800b0100: No signature was present in the subject.

And in fact there is NO prompt during installation of the driver , although domain policy and the “Driver Signing Options” accessed via Device Manager are set to “Warn” . Any ideas how to bring this situation back to normal ?

Christiaan

although you might question your vendor about why it’s unsigned, such as there is no WHQL category for that class of driver or something like that.

If you are trying to do this so you can ship your unfinished product, don’t. Finish it right, then ship it.

Phil

Philip D. Barila
Seagate Technology LLC
(720) 684-1842

“Christiaan Ghijselinck”
Sent by: xxxxx@lists.osr.com
No Phone Info Available
07/02/2005 07:34 AM Please respond to
“Windows System Software Devs Interest List”

To “Windows System Software Devs Interest List”
cc
Subject Re: Re:[ntdev] Allowing unattended installation of unsigned drivers …

> Wouldn’t it be easier to get a test signature for your driver and
> install the base test certificate on the machines where you want to load
> the driver? It takes almost 0 time to test-sign a driver.
> –
> …/ray..

Yes, but as “Gary” stated "

>>>For Server 2003 drivers you can do this by acquiring an Authenticode
>>>certificate and applying it to your install package. This will not work for
>>>XP however. Check Verisign or other such certificate providers.
>>>–
>>>The personal opinion of
>>>Gary G. Little

… this works only on Server2003 . Does anyone knows if this will become
available in XP ( SP’s ) and become/is available in Longhorn ?

Christiaan

>
> Christiaan Ghijselinck wrote:
> > Dear all ,
> >
> > Does exists a method or command line tool that allows to turn off ( allow ) the installation of unsigned drivers without the
user
> > prompt , and that subsequently restores the original setting after installation ? Something that suppresses the user prompt
and
> > simulates OK is all right too . I need this rather urgently , and can’t wait for the “signation” :slight_smile:
> >
> > Thanks ,
> >
> > Christiaan
> >
> >
> >
>
> —
> Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: xxxxx@compaqnet.be
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: xxxxx@seagate.com
To unsubscribe send a blank email to xxxxx@lists.osr.com

— Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256 You are currently subscribed to ntdev as: xxxxx@compaqnet.be To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com

You probably mean “on Intel’s drivers” :slight_smile: Because Intel’s drivers (either
network or video, I now don’t remember, their name starts with “ial*.*”)
often bring it down when we run Verifier HCT tests on our drivers, causing
us to use alternative cards to replace chipset’s devices, to be able to pass
our HCT.

“Alberto Moreira” wrote in message news:xxxxx@ntdev…
Actually maybe Microsoft should get Intel’s signature before they’d be
allowed to run their OS on Intel’s hardware ?

Alberto.
----- Original Message -----
From: cristalink
Newsgroups: ntdev
To: Windows System Software Devs Interest List
Sent: Sunday, July 17, 2005 10:23 PM
Subject: Re:[ntdev] Allowing unattended installation of unsigned drivers


Intel (INTEL!) does not seem to bother signing their motherboard chipset
drivers at all.



“Mark Roddy” wrote in message news:xxxxx@ntdev…
Everytime I install hardware and the driver is unsigned I think ‘here is
a comapny that cannot even be bothered to get their drivers signed’. Signing
is no guarantee of quality, but lack of a signature is a pretty good
indicator of a company that just doesn’t care much about quality.

=====================
Mark Roddy DDK MVP
Windows 2003/XP/2000 Consulting
Hollis Technology Solutions 603-321-1032
www.hollistech.com

--------------------------------------------------------------------------
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Alberto Moreira
Sent: Monday, July 04, 2005 10:17 AM
To: Windows System Software Devs Interest List
Subject: Re: [ntdev] Allowing unattended installation of unsigned
drivers …

Some production software overflows the concept of “signing”. And the
requirements for signing are far too encompassing anyway, so, I take the
opposite viewpoint: unless I need my software to be signed - emphasis on the
need - my attitude is, why bother ? It’s a big drain in manpower, it
extends the product cycle by a significant amount and it may cause the
product to miss a marketing window.

Alberto.

----- Original Message -----
From: Christiaan Ghijselinck
To: Windows System Software Devs Interest List
Sent: Monday, July 04, 2005 2:54 AM
Subject: Re: [ntdev] Allowing unattended installation of unsigned
drivers …

If you are trying to “turn off” unsigned driver warnings in order
to install some software that doesn’t have a signature across your
enterprise, use the domain policy to allow it,

Correct , but the domain policy and the settings within Device
Manager for “Signing” are OR-ed . If one sets te Domain Policy to “allow
unsigned” , the OS will still prompt if the user left ( or has set ) the
default “Prompt” value .

Btw.: On a particular XP system, I get this during normal operation
( setupapi.log ) :

#E360 An unsigned or incorrectly signed file
“D:\WINDOWS\system32\xxxxxxx” for driver “xxxxxxxxx” will be installed
(Policy=Ignore). Error 0x800b0100: No signature was present in the subject.

And in fact there is NO prompt during installation of the driver ,
although domain policy and the “Driver Signing Options” accessed via Device
Manager are set to “Warn” . Any ideas how to bring this situation back to
normal ?

Christiaan

although you might question your vendor about why it’s unsigned,
such as there is no WHQL category for that class of driver or something like
that.

If you are trying to do this so you can ship your unfinished
product, don’t. Finish it right, then ship it.

Phil

Philip D. Barila
Seagate Technology LLC
(720) 684-1842

“Christiaan Ghijselinck”

Sent by: xxxxx@lists.osr.com
No Phone Info Available
07/02/2005 07:34 AM Please respond to
“Windows System Software Devs Interest List”


To “Windows System Software Devs Interest List”

cc
Subject Re: Re:[ntdev] Allowing unattended
installation of unsigned drivers …

> Wouldn’t it be easier to get a test signature for your driver
and
> install the base test certificate on the machines where you want
to load
> the driver? It takes almost 0 time to test-sign a driver.
> –
> …/ray..

Yes, but as “Gary” stated "

>>>For Server 2003 drivers you can do this by acquiring an
Authenticode
>>>certificate and applying it to your install package. This will
not work for
>>>XP however. Check Verisign or other such certificate providers.
>>>–
>>>The personal opinion of
>>>Gary G. Little

… this works only on Server2003 . Does anyone knows if this will
become
available in XP ( SP’s ) and become/is available in Longhorn ?

Christiaan

>
> Christiaan Ghijselinck wrote:
> > Dear all ,
> >
> > Does exists a method or command line tool that allows to turn
off ( allow ) the installation of unsigned drivers without the
user
> > prompt , and that subsequently restores the original setting
after installation ? Something that suppresses the user prompt
and
> > simulates OK is all right too . I need this rather urgently
, and can’t wait for the “signation” :slight_smile:
> >
> > Thanks ,
> >
> > Christiaan
> >
> >
> >
>
> —
> Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as:
xxxxx@compaqnet.be
> To unsubscribe send a blank email to
xxxxx@lists.osr.com
>


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as:
xxxxx@seagate.com
To unsubscribe send a blank email to
xxxxx@lists.osr.com

— Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256 You are currently subscribed to
ntdev as: xxxxx@compaqnet.be To unsubscribe send a blank
email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag
argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag
argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com


Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256

You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
To unsubscribe send a blank email to xxxxx@lists.osr.com

Intel IDE drivers are well-known for this.

Maxim Shatskih, Windows DDK MVP
StorageCraft Corporation
xxxxx@storagecraft.com
http://www.storagecraft.com

----- Original Message -----
From: “Ivan Bublikov”
Newsgroups: ntdev
To: “Windows System Software Devs Interest List”
Sent: Tuesday, July 19, 2005 9:48 PM
Subject: Re:[ntdev] Re:Allowing unattended installation of unsigned drivers …

> You probably mean “on Intel’s drivers” :slight_smile: Because Intel’s drivers (either
> network or video, I now don’t remember, their name starts with “ial*.*”)
> often bring it down when we run Verifier HCT tests on our drivers, causing
> us to use alternative cards to replace chipset’s devices, to be able to pass
> our HCT.
>
> “Alberto Moreira” wrote in message news:xxxxx@ntdev…
> Actually maybe Microsoft should get Intel’s signature before they’d be
> allowed to run their OS on Intel’s hardware ?
>
> Alberto.
> ----- Original Message -----
> From: cristalink
> Newsgroups: ntdev
> To: Windows System Software Devs Interest List
> Sent: Sunday, July 17, 2005 10:23 PM
> Subject: Re:[ntdev] Allowing unattended installation of unsigned drivers
> …
>
>
> Intel (INTEL!) does not seem to bother signing their motherboard chipset
> drivers at all.
>
> –
>
> “Mark Roddy” wrote in message news:xxxxx@ntdev…
> Everytime I install hardware and the driver is unsigned I think ‘here is
> a comapny that cannot even be bothered to get their drivers signed’. Signing
> is no guarantee of quality, but lack of a signature is a pretty good
> indicator of a company that just doesn’t care much about quality.
>
> =====================
> Mark Roddy DDK MVP
> Windows 2003/XP/2000 Consulting
> Hollis Technology Solutions 603-321-1032
> www.hollistech.com
>
>
>
>
>
> --------------------------------------------------------------------------
> From: xxxxx@lists.osr.com
> [mailto:xxxxx@lists.osr.com] On Behalf Of Alberto Moreira
> Sent: Monday, July 04, 2005 10:17 AM
> To: Windows System Software Devs Interest List
> Subject: Re: [ntdev] Allowing unattended installation of unsigned
> drivers …
>
>
> Some production software overflows the concept of “signing”. And the
> requirements for signing are far too encompassing anyway, so, I take the
> opposite viewpoint: unless I need my software to be signed - emphasis on the
> need - my attitude is, why bother ? It’s a big drain in manpower, it
> extends the product cycle by a significant amount and it may cause the
> product to miss a marketing window.
>
> Alberto.
>
> ----- Original Message -----
> From: Christiaan Ghijselinck
> To: Windows System Software Devs Interest List
> Sent: Monday, July 04, 2005 2:54 AM
> Subject: Re: [ntdev] Allowing unattended installation of unsigned
> drivers …
>
>
>
>
>
> If you are trying to “turn off” unsigned driver warnings in order
> to install some software that doesn’t have a signature across your
> enterprise, use the domain policy to allow it,
>
> Correct , but the domain policy and the settings within Device
> Manager for “Signing” are OR-ed . If one sets te Domain Policy to “allow
> unsigned” , the OS will still prompt if the user left ( or has set ) the
> default “Prompt” value .
>
> Btw.: On a particular XP system, I get this during normal operation
> ( setupapi.log ) :
>
> #E360 An unsigned or incorrectly signed file
> “D:\WINDOWS\system32\xxxxxxx” for driver “xxxxxxxxx” will be installed
> (Policy=Ignore). Error 0x800b0100: No signature was present in the subject.
>
> And in fact there is NO prompt during installation of the driver ,
> although domain policy and the “Driver Signing Options” accessed via Device
> Manager are set to “Warn” . Any ideas how to bring this situation back to
> normal ?
>
> Christiaan
>
>
>
> although you might question your vendor about why it’s unsigned,
> such as there is no WHQL category for that class of driver or something like
> that.
>
> If you are trying to do this so you can ship your unfinished
> product, don’t. Finish it right, then ship it.
>
> Phil
>
> Philip D. Barila
> Seagate Technology LLC
> (720) 684-1842
>
>
>
> “Christiaan Ghijselinck”
>
> Sent by: xxxxx@lists.osr.com
> No Phone Info Available
> 07/02/2005 07:34 AM Please respond to
> “Windows System Software Devs Interest List”
>
>
>
> To “Windows System Software Devs Interest List”
>
> cc
> Subject Re: Re:[ntdev] Allowing unattended
> installation of unsigned drivers …
>
>
>
>
>
>
>
>
>
> > Wouldn’t it be easier to get a test signature for your driver
> and
> > install the base test certificate on the machines where you want
> to load
> > the driver? It takes almost 0 time to test-sign a driver.
> > –
> > …/ray..
>
>
> Yes, but as “Gary” stated "
>
> >>>For Server 2003 drivers you can do this by acquiring an
> Authenticode
> >>>certificate and applying it to your install package. This will
> not work for
> >>>XP however. Check Verisign or other such certificate providers.
> >>>–
> >>>The personal opinion of
> >>>Gary G. Little
>
> … this works only on Server2003 . Does anyone knows if this will
> become
> available in XP ( SP’s ) and become/is available in Longhorn ?
>
>
> Christiaan
>
>
>
>
>
> >
> > Christiaan Ghijselinck wrote:
> > > Dear all ,
> > >
> > > Does exists a method or command line tool that allows to turn
> off ( allow ) the installation of unsigned drivers without the
> user
> > > prompt , and that subsequently restores the original setting
> after installation ? Something that suppresses the user prompt
> and
> > > simulates OK is all right too . I need this rather urgently
> , and can’t wait for the “signation” :slight_smile:
> > >
> > > Thanks ,
> > >
> > > Christiaan
> > >
> > >
> > >
> >
> > —
> > Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256
> >
> > You are currently subscribed to ntdev as:
> xxxxx@compaqnet.be
> > To unsubscribe send a blank email to
> xxxxx@lists.osr.com
> >
>
>
> —
> Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as:
> xxxxx@seagate.com
> To unsubscribe send a blank email to
> xxxxx@lists.osr.com
>
> — Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256 You are currently subscribed to
> ntdev as: xxxxx@compaqnet.be To unsubscribe send a blank
> email to xxxxx@lists.osr.com
>
> —
> Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: unknown lmsubst tag
> argument: ‘’
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>
> —
> Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: unknown lmsubst tag
> argument: ‘’
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>
> —
> Questions? First check the Kernel Driver FAQ at
> http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: unknown lmsubst tag argument: ‘’
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>
>
> —
> Questions? First check the Kernel Driver FAQ at
http://www.osronline.com/article.cfm?id=256
>
> You are currently subscribed to ntdev as: xxxxx@storagecraft.com
> To unsubscribe send a blank email to xxxxx@lists.osr.com