I'm developing an app with Tauri and I've signed it with an EV Code Signing Certificate from Sectigo. I've tried signing through Tauri's built in system by inputting the certificate thumbprint and timestamp link (http://timestamp.sectigo.com) and I've tried using signtool, both seem to successfully sign the app, but both result in the same issue.
That is, when users run the msi installer they're still getting the Microsoft Defender SmartScreen warning about an preventing an unrecognized app from running, despite the fact that the EV Code Cert is on the msi installer.
I've tried contacting both Sectigo and Microsoft but neither have exactly been helpful. Does someone know what could be the potential issue?
I'm happy to provide any details as needed, just let me know.
It seems like EV Code Signing Certificates no longer give instant Microsoft Defender SmartScreen reputation anymore (despite the fact that's the whole point). You have to submit your msi/exe to Microsoft and then they'll tell you that your certificate still hasn't established enough reputation, but by submitting your app it'll get rid of the SmartScreen warning for that app.