<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[hMailServer 6.3.1: the installer is signed, and UpdateRequireAuthenticode works]]></title><description><![CDATA[<p dir="auto">Nothing in the server changes. The compiled server differs from 6.3.0 by its version stamp and one comment line. What changes is the installer: the Windows installer is now Authenticode-signed with Azure Artifact Signing, against a certificate profile issued to Progressive Robot Ltd. If you run with <code>UpdateRequireAuthenticode=1</code>, which has existed since 6.2.28, the server's own update path has been refusing every release of this project, because none carried a signature. From 6.3.1 the installer it downloads carries one.</p>
<p dir="auto"><strong>What the upgrade involved</strong></p>
<p dir="auto">The orphan sweep in the 6029 to 6030 upgrade step runs children before parents. Before it adds seventeen foreign keys it deletes rows whose parent is gone, and three of those parent tables are pruned by the same deletes, so pruning an orphaned account, fetch account or distribution list re-orphans rows nothing revisits and the constraint that follows is refused. It affects only an upgrade from a schema below 6030 on a database that already holds orphaned rows, in all four database backends. No installation has reported hitting it, and when it fires it fails loudly with the engine's own words and rolls back. The fix is held for 6.3.2.</p>
<p dir="auto"><strong>The rest</strong></p>
<ul>
<li>Only the Windows installer is signed. There is no Authenticode for a .deb, an .rpm or an AppImage. The elevation prompt now reads the publisher's name.</li>
<li>SmartScreen still warns. Microsoft flags a signed installer as unrecognised until reputation accumulates. An EV certificate would not help; Microsoft removed EV's SmartScreen bypass in 2024.</li>
<li>The <code>UpdateRequireAuthenticode</code> check is WinVerifyTrust on the downloaded installer, and it is Windows-only. On Linux the server says so rather than reporting a pass, and updating is the package manager's job.</li>
<li>The signing gate asked for four of the six settings it guards and never asked about <code>ARTIFACT_SIGNING_ENDPOINT</code> or <code>ARTIFACT_SIGNING_PROFILE</code>. Three outcomes now: none of the six set is a silent no-op, all six signs, anything in between stops and names what is missing.</li>
<li>6.3.0's tagged run attached no Linux packages because the package-install check ran without sudo against /etc/hmailserver, which the package makes 0750 root:hmailserver. It runs under sudo now.</li>
<li>Documentation: the README offers the Linux packages on its download line, and two files that named 6.2.29, a version that does not exist, now say 6.3.0.</li>
</ul>
<p dir="auto">Full suite on the stamped binary: 2,175 tests, 2,166 passed, 0 failed, 9 skipped.</p>
<p dir="auto"><a href="https://www.progressiverobot.com/hmailserver-downloads/" rel="nofollow ugc">Full release notes, checksums and signatures</a></p>
]]></description><link>https://www.hmailserver.co.uk/topic/28179/hmailserver-6.3.1-the-installer-is-signed-and-updaterequireauthenticode-works</link><generator>RSS for Node</generator><lastBuildDate>Wed, 23 Sep 2026 04:33:03 GMT</lastBuildDate><atom:link href="https://www.hmailserver.co.uk/topic/28179.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 11 Sep 2026 03:40:03 GMT</pubDate><ttl>60</ttl></channel></rss>