jimping

Jimping for IT admins

Jimping is a signed Windows ping plotter and continuous traceroute. This page has what a security team needs to review it and allow it on managed devices. On a device you manage, allowing new software is your call; please don't bypass your own policy.

What it does

Code signing

Every release is signed and timestamped with Microsoft Azure Artifact Signing (Public Trust).

Publisher (subject)
CN=James Waller, O=James Waller, L=Lino Lakes, S=mn, C=US
Issuing CA
Microsoft ID Verified CS EOC CA 03
Root
Microsoft Identity Verification Root Certificate Authority 2020
Timestamp
Yes, on every signature

The certificates are short lived (3 days), so a rule on a certificate thumbprint will not cover future versions. Use a publisher rule (the subject and issuer above).

Allowing it, whichever fits your tooling

Verify a download

In PowerShell, from the folder the file is in:

Get-AuthenticodeSignature .\Jimping-setup.exe | Format-List
Get-FileHash .\Jimping-setup.exe

Status should be Valid and the signer CN=James Waller. Compare the hash with the one on the home page.

Questions or a review request: [email protected]