Timestamp Options section of Patch My PC Publisher
Last updated
Was this helpful?
Applies to: Patch My PC Publisher V3.x
Important
This article has not been updated for Version 3.x. Once it has, this banner will be removed.
The Timestamp Options section of Patch My PC (PMPC) Publisher controls how the Publisher applies digital timestamps when signing scripts and CAB files. Timestamping ensures that signatures remain valid after the signing certificate expires and is a recommended best practice for both applications and updates.

Note
For a detailed technical explanation of how timestamping works, including certificate trust, CAB signing, and troubleshooting scenarios, see the following blog post at https://patchmypc.com/blog/demystifying-timestamping-securing-scripts-cab
The Timestamp Server URL defines the timestamp authority used during signing. By default, the Publisher uses the DigiCert timestamp service:
The Use Default option automatically configures the recommended timestamp server. A custom timestamp server can be specified if required by organizational policy.
When Enforce Timestamping is enabled, publishing will fail if timestamping cannot be completed successfully. When this option is not enabled, a timestamping failure is treated as a non terminating error and publishing will continue.
When publishing third party updates to WSUS, update CAB files are timestamped using the Windows Cryptographic API. This process runs under the SYSTEM account on the server.
Because of this behavior, the Cryptographic API uses the proxy configuration defined for the SYSTEM account, not the proxy settings configured in the Publisher.
If the SYSTEM account does not have internet access, timestamping can fail. If the SYSTEM proxy requires authentication, timestamping can also fail because the Cryptographic API does not support interactive proxy authentication.
To validate which proxy settings apply, see Verifying the SYSTEM Proxy Configuration.
Last updated
Was this helpful?
Was this helpful?
http://timestamp.digicert.com