2026-05-15 23:47:10 +02:00
# MrTrust
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
## Brought To You By The Fine People Of MrSphay
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
Good morning, citizen.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
Has Windows ever looked at your freshly downloaded MrSphay program and said:
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
```text
Unknown publisher? Sounds suspicious, pal.
```
Then step right up to **MrTrust ** , the cheerful little trust-onboarding utility that helps your PC recognize signed MrSphay software without poking holes in Windows security.
One click. One confirmation. A brighter tomorrow for properly signed applications.
MrTrust installs public certificates only after you say so. It does not disable Microsoft Defender, SmartScreen, UAC, firewall rules, company policies, common sense, or the big red security lever nobody should touch.
## Download Your Complimentary Trust Appliance
2026-05-15 21:18:19 +00:00
2026-05-16 04:03:06 +02:00
Latest release page:
2026-05-15 21:18:19 +00:00
2026-05-16 04:03:06 +02:00
```text
https://git.wilkensxl.de/MrSphay/MrTrust/releases
```
2026-05-16 04:13:17 +02:00
Download the newest:
```text
MrTrust-<version>.zip
```
Extract it, then run:
2026-05-16 04:03:06 +02:00
```text
MrTrust.exe
```
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
That is the normal user version. It is standalone and carries the public MrSphay certificates it needs.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
## Operating Your Trust-O-Matic 3000
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
Inside the friendly GUI:
2026-05-16 04:03:06 +02:00
2026-05-16 04:13:17 +02:00
- `Install trust` tells Windows to trust MrSphay public signing certificates.
- `Remove trust` politely takes that trust back out again.
- `Refresh` checks whether your PC is currently feeling cooperative.
2026-05-16 04:03:06 +02:00
Default installation scope:
```text
Root certificate -> Cert:\CurrentUser\Root
Code-signing certificate -> Cert:\CurrentUser\TrustedPublisher
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:13:17 +02:00
That means the trust applies only to the current Windows user.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
For all users on the PC, run `MrTrust.exe` as Administrator and choose the all-users option. Please operate administrator privileges responsibly. The future depends on it.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
## How The Magic Works
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
There is no magic. That is how you know it is working.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
The approved flow:
2026-05-16 04:03:06 +02:00
1. A MrSphay app is signed during its release build.
2026-05-16 04:13:17 +02:00
2. You run `MrTrust.exe` .
3. You review the certificate details.
4. You confirm the trust installation.
5. Windows can validate signed MrSphay apps on that PC.
2026-05-16 04:03:06 +02:00
2026-05-16 04:13:17 +02:00
If the app is not signed, MrTrust cannot help it. Even the finest paperwork cannot identify a person who never showed up.
2026-05-16 04:03:06 +02:00
2026-05-16 04:13:17 +02:00
## Safety Notice From The Department Of Not Breaking Windows
MrTrust does not:
- make unsigned programs trusted
- bypass Defender
- bypass SmartScreen
- remove UAC prompts
- silently install certificates
- install private signing keys on user machines
- make sketchy software less sketchy
Windows may still scan, block, warn, quarantine, or ask questions. MrTrust only handles normal certificate trust.
2026-05-16 04:03:06 +02:00
## Public Certificate Values
2026-05-16 04:13:17 +02:00
These values are public and safe to use in documentation, agent prompts, and integration metadata:
2026-05-16 04:03:06 +02:00
```text
Publisher:
MrSphay
Root certificate thumbprint:
39F7458E6E2C1126E93E6A1F228196006B174DF2
Code-signing certificate thumbprint:
A024A89200469F099EC4A172B4F96F6428AFD41B
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:13:17 +02:00
They are also stored here:
2026-05-16 04:03:06 +02:00
```text
assets/certificates/thumbprints.txt
mrtrust.integration.json
```
2026-05-16 04:13:17 +02:00
## For The Workshop Crew
2026-05-16 04:03:06 +02:00
Local maintainer commands:
2026-05-15 21:18:19 +00:00
```powershell
2026-05-15 23:47:10 +02:00
.\MrTrust.ps1 gui
2026-05-16 04:03:06 +02:00
.\MrTrust.ps1 install
.\MrTrust.ps1 uninstall
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:03:06 +02:00
Create or refresh local certificates:
2026-05-15 21:18:19 +00:00
```powershell
2026-05-16 04:03:06 +02:00
.\scripts\New-MrTrustCertificate.ps1
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:03:06 +02:00
Build a release ZIP locally:
2026-05-15 21:18:19 +00:00
```powershell
2026-05-16 13:05:12 +02:00
.\scripts\New-MrTrustRelease.ps1 -Version 0.1.4
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:03:06 +02:00
Sign an artifact locally on Windows:
2026-05-15 21:18:19 +00:00
```powershell
2026-05-16 04:03:06 +02:00
.\MrTrust.ps1 sign `
-Path "C:\Path\To\App.exe" `
-CertificateThumbprint A024A89200469F099EC4A172B4F96F6428AFD41B
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:13:17 +02:00
Private signing material belongs only in:
```text
private/
Bitwarden
Gitea repository secrets
```
Never commit `.pfx` files, private keys, passwords, or Base64-encoded signing material. That is not trust. That is handing out the vault keys at the snack counter.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
## Gitea Secrets For Other Projects
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
For another project to sign Windows release artifacts on an Ubuntu Gitea runner, add these secrets to that target repository:
2026-05-15 21:18:19 +00:00
2026-05-16 04:03:06 +02:00
```text
MRTRUST_CODESIGN_PFX_BASE64
MRTRUST_CODESIGN_PFX_PASSWORD
```
Optional timestamp override:
2026-05-15 21:18:19 +00:00
```text
2026-05-16 04:03:06 +02:00
MRTRUST_TIMESTAMP_URL
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:13:17 +02:00
The first two values are private signing credentials. Keep them in Bitwarden and Gitea Secrets only.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
Ubuntu helper script:
2026-05-16 04:03:06 +02:00
```text
scripts/Sign-MrTrustProjectLinux.sh
2026-05-15 21:18:19 +00:00
```
2026-05-16 04:03:06 +02:00
It signs supported Windows artifacts with `osslsigncode` :
2026-05-16 01:46:36 +02:00
2026-05-16 04:03:06 +02:00
```text
.exe
.msi
.dll
.cat
```
2026-05-15 21:18:19 +00:00
2026-05-16 04:03:06 +02:00
PowerShell scripts should be signed on Windows, not Ubuntu.
2026-05-16 01:46:36 +02:00
2026-05-16 04:13:17 +02:00
## Installing MrTrust Into Another Project
2026-05-16 02:03:25 +02:00
2026-05-16 04:13:17 +02:00
Give your coding agent this repository:
2026-05-16 02:03:25 +02:00
2026-05-16 04:03:06 +02:00
```text
https://git.wilkensxl.de/MrSphay/MrTrust
```
2026-05-16 01:46:36 +02:00
2026-05-16 04:13:17 +02:00
Tell it to read:
2026-05-15 21:18:19 +00:00
2026-05-16 04:03:06 +02:00
```text
mrtrust.integration.json
docs/agent-target-integration.md
docs/integration-prompt.md
```
2026-05-16 04:13:17 +02:00
The target project should end up with:
2026-05-16 04:03:06 +02:00
2026-05-16 04:13:17 +02:00
- signed Windows release artifacts
- a visible optional MrTrust setup path
- a link to or bundled copy of `MrTrust.exe`
- documentation for installing and removing trust
- no committed private signing material
2026-05-16 04:03:06 +02:00
2026-05-16 04:13:17 +02:00
Remember the two-part handshake:
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
- MrTrust side: the user installs public trust certificates once.
- Target project side: the app is signed with the MrSphay code-signing certificate.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
No signature, no trust. No trust, no victory parade.
2026-05-15 21:18:19 +00:00
2026-05-16 04:03:06 +02:00
## Current Build
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
The Gitea workflow builds `MrTrust.exe` on `ubuntu-latest` with .NET Windows cross-targeting.
On pushes to `main` , it:
2026-05-16 04:03:06 +02:00
2026-05-16 04:13:17 +02:00
1. builds the standalone Windows executable
2026-05-16 13:05:12 +02:00
2. packages `MrTrust-0.1.4.zip`
2026-05-16 04:13:17 +02:00
3. uploads the workflow artifact
4. attaches the ZIP to the Gitea release
2026-05-16 04:03:06 +02:00
2026-05-16 04:13:17 +02:00
Manual `workflow_dispatch` runs build artifacts but do not attach release assets. This prevents duplicate release uploads, which are bad for morale and paperwork.
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
## Final Safety Reminder
2026-05-15 21:18:19 +00:00
2026-05-16 04:13:17 +02:00
MrTrust is intentionally visible and reversible:
- the GUI shows the trust state
- installation requires confirmation
- removal is available in the same tool
- public certificates are embedded in the executable
- private signing material is never needed on user machines
2026-05-16 02:03:25 +02:00
2026-05-16 04:03:06 +02:00
For broad public distribution without SmartScreen reputation delays, a recognized commercial code-signing certificate is still the cleanest option.
2026-05-16 04:13:17 +02:00
Thank you for choosing MrTrust. Stay signed, stay verified, and keep your release pipeline tidy.