OnPrem Signing Certificate
I'm trying to start a thread for us to discuss the latest bombshell that we have 6 days to provide our own code signing certificates, my previous attempt is "Awaiting Moderation" which may just be because I included a URL in the post?
While it feels very much like a final attempt to kill off the on-prem user base, there's no real benefit discussing that other than venting so I'm looking to see if anyone's research so far as turned up an affordable way of acquiring code signing certificates.
The likes of DigiCert, SSL etc seem to come out at several hundred $/year in the first year, possibly dropping from there once you own a suitable storage method for the certificate.
Azure Trusted Signing looked promising for a while at a few $ a month - but is currently only available to USA and Canada based businesses, so rules out the rest of us.
Does anyone have any other sources?
Thanks
Andrew
In some ways, that's part of the risk with perpetual software that is out of maintenance/support. At any moment some incompaibility or showstopper could arise that makes your older version unusable. There could be a windows update next week that does the same. I don't think you'd have much of a leg to stand on.
I think the previous patch was supplied as a security issue and I'm assuming was trivial to patch the older versions. The changes related to code signing unlikely to be so trivial. With this latest certificate revocation, I suppose you can keep running it with the revoked certificate, it's just you'll run into issues with Windows and A/V potentially trying to block it.
To clarify, we run a perptual license with active maintenance going to back to the Elsinore days as well. We get really good pricing on ScreenConnect so even with the code signing certificate it's still a bargain.
The process of obtaining and installing a code signing certificate didn't end up being overly arduase, there was just a few things that weren't immediately clear from both ScreenConnect's side and the process of actually procuring a code signing cert and getitng it into Azure Key Vault. The actual process itself, if I had to do it again, would be quite straight forward.
@Perry Diels, I think it'd only be a legal issue if the main or sole intent was to block perpetual license holders out of maintenance from running the software, which clearly isn't the case here. I'm not defending ScreenConnect though, they should have been more proactive in coming up with a better long-term solution (e.g. architectural changes) BEFORE it became an emergency. Code signing like they were, and now expecting customers to get a code signing certificate are both ridiculous. I'm guessing if still owned by Elsinore we perhaps wouldn't have been faced with this situation.
@Wardrop The situation is NOT one where we applied an operating system upgrade that "broke" another party's software. ConnectWise has proactively "reached out" to cause existing on-prem servers to be unusable (as they did in early 2024) or untrustworthy (as they just did in 2025). This was functional, paid-for software which they "broke", and then try to coerce us into spending hundreds of thousands of dollars on their SAAS platform.
This is as if the manufacturer of your automobile remotely turned your car off and wouldn't give you access to make it run anymore.
You must be a shill for ConnectWise if you think you can justify their actions.