Verification outcome for an application's code signature, normalized across the platform verifiers: Code Signing Services (SecStaticCodeCheckValidityWithErrors) on macOS, Authenticode (WinVerifyTrust) on Windows, and snap store publisher attribution on Linux. INVALID indicates tampering or corruption of signed code; UNTRUSTED and REVOKED indicate the signature is cryptographically intact but the signing identity must not be trusted. Reference: Code Signing Services Reference: WinVerifyTrust function (wintrust.h)
Values
| Enum Value | Description |
|---|---|
|
|
The verifier produced no usable result; the signing state could not be determined. |
|
|
No code signature is present. On Linux this includes snap packages not delivered by the snap store. |
|
|
The signature is cryptographically valid and its certificate chain is trusted by the operating system. |
|
|
macOS only: the code is ad-hoc signed (codesign identity "-"). The code directory is sealed but carries no signing certificate chain, so no signer identity can be attributed or trusted. |
|
|
The signature does not verify: the code or the signature itself was modified or is corrupt. |
|
|
The signature is intact but its certificate chain is not trusted by the operating system, for example an untrusted or expired root. |
|
|
The signing certificate has been revoked. Treat the application as compromised. |
Used by
ApplicationSignaturetype: Code-signing verification state of an ApplicationInstall, evaluated on the endpoint by the platform's native verifier.
Example
Example
"UNKNOWN"