Es gab ein Problem beim Laden der Kommentare.

How to verify integrity of our own (alternative) installer setups.

HelpDesk  »  Knowledgebase  »  Artikel betrachten


Verifying Installer Integrity & Origin

The verification methods described below apply exclusively to our own installers!

Those are built using install4j and are digitally signed to ensure they have not been altered by third parties.

 

To ensure that the software you downloaded is authentic and has not been tampered with, we recommend verifying its Digital Signature.

A digital signature confirms the identity of the software publisher and ensures the file’s integrity.

 

How to Check Using VirusTotal

You can easily verify the signature of both Windows (.exe) and macOS (.dmg, .pkg) installers without installing additional software:

  1. Upload the File: Go to www.virustotal.com and upload your installer file.

  2. Open the Details Tab: Once the scan is complete, click on the "Details" tab at the top of the results page.

  3. Check the "Signature Info" Section: Scroll down until you find the section labeled "Signature Info" (for Windows) or "File Signature" (for macOS).

What to Look For

  • Verified Status: You should see a status like "Signed" or "Valid".

  • Signers/Authority: Look at the "Signers" field. It should clearly list the name of our organization: AppWork GmbH.

Important: If VirusTotal reports the file as "Unsigned" or the signer's name does not match our organization, do not run the installer and contact our support team immediately.

Verified Signer Information

The signature should clearly list our organization. Depending on the version of the software you are installing, the certificate may vary.

Please compare the Signer and Thumbprint with the list below:

 

Please note: The following list provides the most common certificates used for our installers. While we strive for accuracy, this list may not be exhaustive, particularly regarding older legacy versions or historical certificates.

 

Windows (.exe)

Status Name Issuer Valid From / To Serial Thumbprint
Current Appwork GmbH GlobalSign

02:36 PM 10/22/2026

02:36 PM 07/26/2023

6C 96 BF A2 6C 9F

9D 8E 84 38 26 31

78C97D5FDE66893DDEF99033372A76D0D1B84C7D

Previous Appwork GmbH GlobalSign

01:49 PM 10/13/2023

01:58 PM 04/21/2021

35 98 95 82 3C 34

08 0D C0 7D C7 D4

2EAA8DE0BE4828964D6D922224A7A265D0A96369

Previous AppWork GmbH GlobalSign

01:49 PM 10/13/2023

01:49 PM 07/13/2020

1B C4 59 B0 42 5B

1D 82 B6 1C 99 62

94F54C365C8A60A0A0057D47944FBA5E8B1AD9FA

macOS (.dmg, .pkg)

Status Name Issuer Valid From / To Serial Thumbprint
Current Appwork GmbH Apple Inc.

10:12 PM 02/01/2027

10:10 AM 01/11/2024

33 F4 BE 81 52 42 C2 CC AD1CA0CCF62758A8A464FB50D60C8FFCEF5C44B1
Previous AppWork GmbH Apple Inc.

12:51 PM 09/15/2023

12:51 PM 09/14/2018

71 C1 55 73 D9 E5 AB AD FFE38D8D8D9D6E3B1685201F3E0390748B06105F

Alternative: Checking Locally

If you prefer not to upload the file, you can also check the signature directly on your computer:

  • Windows: Right-click the file → PropertiesDigital Signatures tab. Select the signature and click Details.

  • macOS: macOS does not show digital signature details in the standard "Get Info" window

Verification for Linux Shell Scripts and JDownloader.jar

Please note that the detailed verification instructions and GPG infrastructure for our Linux installers (.sh) and the generic Java archive (JDownloader.jar) are currently under development.

We are in the process of setting up our official GPG signing environment to ensure the highest security standards for these platforms. Step-by-step guides and our public keys will be published here shortly.


Ähnliche Artikel


On-Premise Help Desk Software by SupportPal