A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Artifact Signing EOC CA 04: publisher-mapping issue or ordinary new-file reputation?
We publish NinePane Connector for Windows. Our intended 0.8.56 installer is signed through Microsoft Artifact Signing and currently passes Authenticode verification as NINEPANE STUDIO. Microsoft Edge nevertheless displays an uncommon-download warning.
Candidate details:
- Filename:
NinePane-Connector-Setup-0.8.56-Windows-x64.exe - Size: 101,427,048 bytes
- SHA-256:
69822b978d2fcc4a9dfc04eaeb41c1c598e95686b738944ce0ba01f8d7c00c06 - Embedded RFC3161 timestamp:
2026-09-08T19:25:20.113Z - Publisher certificate thumbprint:
1F20C29C275AF5DE90557D836A7C96C52AF75306 - Intermediate: Microsoft ID Verified CS EOC CA 04
- Intermediate thumbprint:
4FD41636DC2ACDFBD5A8C471186E43DF7DBFB384 - Intermediate validity begins:
2026-03-26T18:11:31Z
These identify the intended local candidate, not a hash-verified completed browser download. A valid signature does not prove software safety or browser clearance.
An earlier Microsoft support discussion reported the intermediate-CA reputation propagation problem corrected on June 18. Later July follow-up requested hashes and certificate thumbprints. Our installer was signed in September, after those updates. We have no established previously warning-free baseline and are not claiming a demonstrated regression or that this CA issue caused our warning.
How can we distinguish ordinary new-file reputation from a remaining publisher-identity mapping issue, and what non-sensitive evidence would help?
Could you clarify the supported publisher route when the Artifact Signing FAQ suggests file assessment but Windows developer guidance says consumer reputation has no manual review mechanism? Our Basic Azure support plan does not permit a private technical ticket. Is a free, secure route available without making the authenticated pre-release installer public?
No installer, credentials, private download links or diagnostic logs are attached. We are not requesting a warning bypass.