Guidance on signing Windows executables, PowerShell scripts, and Java applications in compliance with the CA/B Forum hardware token mandate.
Effective June 1, 2023, the CA/Browser Forum mandated that private keys for all publicly trusted Code Signing certificates (both Standard OV and Extended Validation EV) must be stored on qualifying secure hardware (FIPS 140-2 Level 2 or Common Criteria EAL 4+):
Pre-configured USB hardware security token (SafeNet eToken 5110) delivered directly to your organization by the CA.
Generate private key and CSR on a supported device (YubiKey 5 FIPS or Luna HSM) with cryptographic attestation.
Modern cloud-native signing solutions such as DigiCert ONE Software Trust Manager or Sectigo Certificate Manager.
signtool sign /tr http://timestamp.digicert.com /td sha256 /fd sha256 /a "C:\Release\setup.exe" jarsigner -tsa http://timestamp.sectigo.com -keystore NONE -storetype PKCS11 app.jar myalias Browse our comprehensive catalog of DV, OV, and EV certificates from Sectigo, DigiCert, and GeoTrust with instant issuance and 24/7 technical validation support.
The premier marketplace for seamless SSL certificate issuance, renewal, and website trust management worldwide.
Global Certificate Distribution Hub
Support: support@renewalssl.com
Knowledge Base & Guides
CSR Generator Guide
Contact Support Team
Client Portal Login
View Shopping Cart
Quick Checkout
© 2026 RenewalSSL.com. All rights reserved.
Next-gen PKI platform. Manage digital trust at enterprise scale.
Automate the full certificate lifecycle. Stay secure and compliant.
Simplify certificate lifecycle management across your entire network.
Automate the full certificate lifecycle. Stay secure and compliant.
Protect software supply chains. Ensure secure code delivery.
Digitally sign and validate documents. Preserve integrity and origin.