Jump to content

Firewall rules for digitally signed applications with Unicode characters in the publisher name do not work correctly


labynko

Recommended Posts

Hello.

If the application has Unicode characters in the digital signature publisher name, the firewall rules that are configured to check the digital signature will not work correctly: notifications about the rule triggering do not work and connections to public addresses are blocked. As an example, we can use the WinBox program from MikroTik.

https://download.mikrotik.com/routeros/winbox/3.41/winbox64.exe

Digital signature publisher name for WinBox64.exe:

SIA "Mikrotīkls"

image.thumb.png.032ee0188559c3c7b5372242bf96d480.png

Example of a working rule:

image.thumb.png.e08a17632628dce86cc315fa33a56ee8.png

An example of a rule that does not work correctly:

image.thumb.png.605fd793e0af2771351622690642b874.png

The issue is reproduced in the current version of ESET Endpoint Security 11.1.2052.0.

Link to comment
Share on other sites

  • Administrators

We confirmed the bug but it's not caused by a unicode string. It will be addressed via a firewall module update automatically.

M_EPFW-393

Link to comment
Share on other sites

  • Administrators

It's nested quotes in CN which causes the cert. to be considered invalid. A fix will be included probably included in the firewall module 1452. We're currently in the process of releasing module 1451.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...