DigiCert Code Signing Certificates

DigiCert Code Signing Certificates

Stop software and application tampering and show customers their downloads are secure

DigiCert Code Signing Certificates

DigiCert Code Signing Certificates

Pair your GeoTrust certificate with a DigiCert Code Signing Certificate to show customers, app stores and operating system providers that no third parties have tampered with your code.

Perfect for security-conscious organizations and software developers, your code signing options include cloud-based secure key private storage or the high-assurance Extended Validation (EV) that Microsoft Windows drivers require for signing.

Read More >
  • 24x5 Standard Support
  • FIPS 140-2 Level 2-compliant key storage (KeyLocker)
  • DigiCert CertCentral certificate management platform
  • EV compatible with Microsoft attestation signing requirements

DigiCert Code Signing Certificates

DigiCert Code Signing Certificates

Pair your GeoTrust certificate with a DigiCert Code Signing Certificate to show customers, app stores and operating system providers that no third parties have tampered with your code.

Perfect for security-conscious organizations and software developers, your code signing options include cloud-based secure key private storage or the high-assurance Extended Validation (EV) that Microsoft Windows drivers require for signing.

Read More >
  • 24x5 Standard Support
  • FIPS 140-2 Level 2-compliant key storage (KeyLocker)
  • DigiCert CertCentral certificate management platform
  • EV compatible with Microsoft attestation signing requirements
Code Signing Certificates

Features

Code signing certificates don’t just protect your organization. They also prevent security warnings, help you meet platform requirements, and make sure whatever you build is secured by the highest level of digital trust.

Multi-factor Authentication

Two-Factor Authentication (2FA) signing with a USB token.

Identity Verification

Verification to prove intellectual property, plus tamper protection and proof of authenticity.

Timestamping

Timestamped certificates ensure added security—any code with an expired signature must be re-signed.

Signing Authorization

Authorized-only HSM certificate keys for signing control.

Specifications

Platforms

  • Apache ANT & Maven
  • Azure DevOps
  • CircleCI
  • GitLab
  • Gradle
  • Jenkins

Client-Side Libraries

  • Apple CryptoTokenKit
  • Microsoft KSP
  • PKCS11
  • SmartCard Daemon

Marketplace Plug-in

  • Azure Visual Studio Marketplace
  • Github
  • Jenkins

Frequently Asked Questions


By attaching a digital certificate to your code, code signing enables confirmation that digital binaries haven’t been altered. Using Public Key Infrastructure (PKI), a code signing certificate attests to the integrity of the code or software while attaching a cryptographically unique user and timestamp to show when and by whom the code was signed.


Firmware, applications, drivers, mobile apps, containers, source code artifacts, and all other all types and forms of digital binaries can all be signed with a code signing certificate. 


As of June 1, 2023, code signing certificate key pairs must be issued and stored in a Hardware Security Module (HSM) that meets or exceeds FIPS 140-2 Level 2 or Common Criteria EAL 4+ standards to ensure the private key is protected and unexportable.


DigiCert uses secure tokens to set up private keys, in compliance with CA/B Forum regulations. You can use your own token (which you must set up to sign code) or get one from DigiCert. Read about the setup process here.


DigCert certificate subscriptions allow you the flexibility to easily replace or reconfigure certificates and other licensed products, simplify budgeting by annualizing the fees associated with your certificates, and automate license renewals for streamlined certificate lifecycle management.

Learn how DigiCert solutions can
help you deliver digital trust

By supplying my personal information and clicking submit, I agree to receive communications about DigiCert products and services, and I agree to DigiCert and its affiliates processing my data in accordance with DigiCert's Privacy Policy.