Hewlett -Packard has notified some customers that it will revoke a digital certificate used to sign a vast array of software, including hardware drivers and other software needed to run on older HP computers. The certificate has been revoked because the company learned that it had been used to digitally sign malware that had infected a developer's computer.
An HP said the certificate itself had not been compromised and that he had recently been notified about the malware — a four-year-old Windows Trojan — by Symantec. Wahlin said the malware, which had infected an HP employee’s computer, had accidentally been digitally signed as part of a separate software package and then sent a signed copy of itself back to its point of origin. Although the malware has since been distributed over the Internet while carrying an HP certificate, Wahlin noted that the Trojan was not shipped to HP customers as part of the software package.
Regardless of the outcome, the revocation of the certificate requires HP to proceed with reissuing a large number of software packages with a new digital signature. The full impact of the certificate revocation will not be disclosed until Verisign revokes the certificate on October 21, Wahlin said.

