Code-signing verification state of an ApplicationInstall, evaluated on the endpoint by the platform's native verifier. Reference: Code Signing Services Reference: WinVerifyTrust function (wintrust.h)
Fields
| Field Name | Description |
|---|---|
status - ApplicationSignatureStatus!
|
Outcome of the signature verification. See ApplicationSignatureStatus for the meaning of each value. |
signer - String!
|
Human-readable signer identity: the organization of the leaf signing certificate (macOS Developer ID / Windows Authenticode subject), or the snap store publisher on Linux. Empty when the application is unsigned, ad-hoc signed, or the signer could not be determined. |
thumbprint - String!
|
Lowercase hex SHA-256 fingerprint of the DER-encoded leaf signing certificate. Currently reported on macOS only; empty when no certificate chain is available (unsigned or ad-hoc signed) and on other platforms. |
teamIdentifier - String!
|
Apple Developer Program Team ID of the signing identity (macOS only). Empty on other platforms and for unsigned or ad-hoc signed applications. |
signedAt - Time
|
Secure timestamp embedded in the signature (macOS secure timestamp / Authenticode countersignature). Null when the signature carries no timestamp or the application is unsigned. |
Used by
ApplicationInstalltype: One installed copy of an application on one Endpoint.
Example
Example
{
"status": "UNKNOWN",
"signer": "abc123",
"thumbprint": "abc123",
"teamIdentifier": "xyz789",
"signedAt": "2021-10-07T18:23:25.829Z"
}