Changes between Version 24 and Version 25 of BuildingTapWindows6
- Timestamp:
- 04/19/18 13:17:48 (4 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
BuildingTapWindows6
v24 v25 5 5 Generic build instructions for tap-windows6 [https://github.com/OpenVPN/tap-windows6/blob/master/README.rst are available] in it's Git repo. This page contains additional information that is more generic and not really suitable for inclusion in the main documentation. 6 6 7 = Codesigningrequirements =7 = Generic requirements = 8 8 9 9 Getting the [https://msdn.microsoft.com/en-us/library/windows/hardware/ff686697%28v=vs.85%29.aspx Authenticode signatures] right so that all Windows versions detect them can be quite tricky. This seems to be particularly true for kernel-mode driver packages. The Authenticode signatures have a few requirements: … … 16 16 The build computer should have WinDDK 7600.* installed, because currently buildtap.py does not work on anything newer. 17 17 18 = = Supporting Windows Vista ==18 = Building with support for Windows Vista = 19 19 20 20 If the driver has to support Windows Vista or very old Windows 7 versions it has to have two signatures: … … 103 103 If this process sounds complicated, that's because it is. At some point would make sense to adapt buildtap.py to add both signatures automatically, which would simplify the process dramatically. However, that would require porting buildtap.py to Windows Kit 10, which would require a non-trivial amount of work. 104 104 105 = Supporting Windows 7 and later = 106 107 '''TODO''' 105 = Building for Windows 7 and later = 106 107 Any relatively recent Windows 7 installation supports SHA2 Authenticode signatures. This means that the laborious and fragile dual-signature process can be avoided. You only need the EV SHA2 kernel-mode code-signing certificate, which probably comes in the form of a dongle that integrated with Windows certificate store. Optionally you may sign the tap-windows6 installer with a non-EV SHA2 code-signing certificate. 108 109 The build process is somewhat easier than with dual signatures. 110 111 '''On build computer''' 112 113 '''On code-signing computer''' 108 114 109 115 = Useful commands =