Skip to content

Windows Smart App Control blocks official tunnel-client v0.0.14 (unsigned Windows amd64 binary) #68

Description

The official Windows amd64 full-client release v0.0.14 cannot start on a Windows 11 system with Smart App Control enabled. Windows reports that an application control policy blocked the file; CodeIntegrity events 3033 and 3077 report failure to meet signing requirements under policy 0283ac0f-fff1-49ae-ada1-8a933130cad6. Authenticode reports NotSigned.

Verified release: https://github.com/openai/tunnel-client/releases/tag/v0.0.14

  • Asset: tunnel-client-v0.0.14-windows-amd64.zip
  • ZIP SHA256: 784ab8da7b5a88f0109f1fd8aaf0a1c86067430b896dddf307ef7e3cc49fa1a5, matching the GitHub release asset digest.
  • Extracted executable SHA256: fcc85a69ec0ad82518e4f8964f60c45e31787957782a0fc9c1b0c44e82d61b9b, identical to the installed executable.
  • Even invoking tunnel-client.exe run --help is blocked before runtime authentication.
  • The local Node MCP server responds correctly; existing tunnel metadata authentication succeeds. The disconnected connector returns HTTP 404.

Please provide a Windows build with a valid trusted Authenticode signature, or an official resolution that preserves Smart App Control. We have not disabled protection or attempted to evade the block. Is signing planned, and is a supported signed distribution available?

Microsoft documents that Smart App Control does not offer an individual-app exception and recommends a valid developer signature: https://support.microsoft.com/en-us/windows/security/threat-malware-protection/smart-app-control-frequently-asked-questions

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions