Therefore after the certificate expires, Windows and other tools will treat the signature as invalid.To avoid having the signature invalidated please add option /t <a href="http://timestamp.verisign.com/scripts/timstamp.dll">http://timestamp.verisign.com/scripts/timstamp.dll</a> when you next time invoke "signtool.exe sign.