# Timestamping from FinalBuilder fails almost every time since a few days

**URL:** https://www.finalbuilder.com/forums/t/timestamping-from-finalbuilder-fails-almost-every-time-since-a-few-days/7266
**Category:** Discussion
**Created:** [August 8, 2022, 1:47pm UTC](https://www.finalbuilder.com/forums/t/timestamping-from-finalbuilder-fails-almost-every-time-since-a-few-days/7266 "2022-08-08T13:47:13Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![jonjon](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/j/77aa72/32.png) [@jonjon](https://www.finalbuilder.com/forums/u/jonjon)
#### Post date: [August 8, 2022, 1:47pm UTC](https://www.finalbuilder.com/forums/t/timestamping-from-finalbuilder-fails-almost-every-time-since-a-few-days/7266/1 "2022-08-08T13:47:13Z")

</div>

Hi, I’ve been using [this sample](https://github.com/VSoftTechnologies/FinalBuilder.Examples/blob/master/FB8/CodeSigning/CodeSigningExample.fbp8) from [this blog post](https://www.finalbuilder.com/resources/blogs/code-signing-changes-for-2016) for years now without problems.  
But for a few days now, I (almost) always get an error when timestamping files:

SignTool Error: An error occurred while attempting to timestamp: XXXXXXXX  
SignTool Error: An unexpected internal error has occurred.  
Error information: “SignerTimeStamp() failed.” (-2147012889/0x80072ee7)

I’m still using the same version of SignTool.exe, with the same certificate that I’ve been using for years.  
I suspect that values set in the SHA1TimeStampServers and SHA2TimeStampServers are not working or reliable anymore. Could that be the source of this problem ? If so, what would be the recommended up-to-date timestamp servers to use for both of those variables ?

Thanks.

---

<div class="post-metadata">

### Author: ![Vincent](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/vincent/32/938_2.png) [@Vincent](https://www.finalbuilder.com/forums/u/Vincent)
#### Post date: [August 8, 2022, 10:23pm UTC](https://www.finalbuilder.com/forums/t/timestamping-from-finalbuilder-fails-almost-every-time-since-a-few-days/7266/2 "2022-08-08T22:23:12Z")

</div>

I suspect the issue is the sha1 time stamp servers have all been turned off, since SHA1 is no longer accepted, and I believe the root certificates have all expired.

> **[Timestamp Requests and SHA-1 Deprecation - Entrust Blog](https://www.entrust.com/blog/2022/05/timestamp-requests-and-sha-1-deprecation/)**
>
> Entrust hosts a time-stamp authority (TSA) to support our customers who digitally sign data such as code and documents. When a digital signature is

> **[The truth about SHA1, SHA-256, dual-signing and Code Signing Certificates](https://support.ksoftware.net/support/solutions/articles/215805-the-truth-about-sha1-sha-256-dual-signing-and-code-signing-certificates-)**
>
> \*\*PLEASE NOTE: As of May 30th 2020, SHA1 timestamping is effectively deprecated as the SHA1 roots have expired. Use only the SHA256 timestamp server from now on - http://timestamp.comodoca.com/?td=sha256. The SHA256 transition that Microsoft a...

So the answer is to turn off the SHA1 signing and only do SHA256

This is the list of timestamp servers we are currently using

```auto
http://timestamp.digicert.com
http://timestamp.comodoca.com/authenticode
http://tsa.starfieldtech.com/
http://www.trustcenter.de/codesigning/timestamp

```
