winsign is a python module for signing and manipulating Authenticode signatures in PE and MSI files.
Works on Python 3.11 and up.
Free software: MPL2
Requirements
Most dependencies are specified in pyproject.toml, however, currently you also need osslsigncode installed to perform signing. This utility can be fetched from your distribution’s package repository, or from e.g. https://github.com/mtrojnar/osslsigncode
Signing MSIX/APPX files currently requires Mozilla’s fork of msix-packaging.
Installation
pip install winsign
CLI Usage
usage: winsign [-h] --certs CERTS --key PRIV_KEY [-n COMMENT] [-i URL] -d
{sha1,sha256} [-t {old,rfc3161}] [-v] [-q]
infile [outfile]
positional arguments:
infile unsigned file to sign
outfile where to write output to. defaults to infile
optional arguments:
-h, --help show this help message and exit
--certs CERTS certificates to include in the signature
--key PRIV_KEY private key used to sign
-n COMMENT comment to include in signature
-i URL url to include in signature
-d {sha1,sha256} digest to use for signing. must be one of sha1 or sha256
-t {old,rfc3161}
-v, --verbose
-q, --quiet
Future plans
Stop using osslsigncode for PE signatures
Refactor code so that osslsigncode functionality is in its own module
Add python support for MSI, then we can drop dependency on osslsigncode
Development
- Highly recommended to create a virtualenv, then run:
pip install -e .
make your changes to the source files
run local tests: tox
- upon successful r+ and merging to master branch, you need to release a new version on PyPi.
edit pyproject.toml to adjust the version
generate .whl file locally: python setup.py bdist_wheel
file will exist in: ./dist/winsign-{version}-py3-none-any.whl
(assuming you have pypi access to upload)
upload to pypi: twine upload –verbose dist/winsign-{version}-py3-none-any.whl
Credits
Chris AtLee
Ben Hearsum <bhearsum@mozilla.com>
Joel Maher <jmaher@mozilla.com>
Metadata
Release files for winsign 2.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| winsign-2.3.0.tar.gz | 46.7 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| winsign-2.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 46.7 MB
Release files / winsign-2.3.0.tar.gz
| Download URL | winsign-2.3.0.tar.gz |
|---|---|
| Size | 46.7 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d850339143a43888280cf95657b4b068c07e1b5a13ab51e01c9b52be3d7b983e
|
|
BLAKE2b-256 checksum How to use checksums |
023c10d2cb98db0799cf84bb8833bf25c7f6d0af0028d8f0a28fc3c2f3597523
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 25, 2026.
Transparency logRelease files / winsign-2.3.0-py3-none-any.whl
| Download URL | winsign-2.3.0-py3-none-any.whl |
|---|---|
| Size | 32.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8a86382a6200be0abd7c00f9807aa696e5b5a3f82b64d4c28c74ca9e438dbbec
|
|
BLAKE2b-256 checksum How to use checksums |
7d9a8c79782d069a6abca9204a62a2779cde43dc1f20d723771b18550df0c50f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Feb 25, 2026.
Transparency log