24/7 Validation Support · Certificates issued in minutes
0
/ Code Signing Tutorials
TUTORIAL 05 • SOFTWARE INTEGRITY

Code Signing Certificate Tutorials

Guidance on signing Windows executables, PowerShell scripts, and Java applications in compliance with the CA/B Forum hardware token mandate.

CA/B Forum Hardware Mandate
FIPS 140-2 Level 2+ Tokens
Signtool & Jarsigner
SmartScreen Reputation
REGULATORY MANDATE

The CA/B Forum Hardware Token Requirement

Effective June 1, 2023, the CA/Browser Forum mandated that private keys for all publicly trusted Code Signing certificates (both Standard OV and Extended Validation EV) must be stored on qualifying secure hardware (FIPS 140-2 Level 2 or Common Criteria EAL 4+):

DELIVERY 01

CA-Shipped Physical Token

Pre-configured USB hardware security token (SafeNet eToken 5110) delivered directly to your organization by the CA.

DELIVERY 02

Customer-Owned Hardware (BYOH)

Generate private key and CSR on a supported device (YubiKey 5 FIPS or Luna HSM) with cryptographic attestation.

DELIVERY 03

Cloud HSM Signing Service

Modern cloud-native signing solutions such as DigiCert ONE Software Trust Manager or Sectigo Certificate Manager.

SIGNING WORKFLOWS & RFC 3161 TIMESTAMPING

Command Line Software Signing Examples

1. Sign Windows Executable (.exe) with Signtool & RFC 3161 Timestamping
signtool sign /tr http://timestamp.digicert.com /td sha256 /fd sha256 /a "C:\Release\setup.exe"
2. Sign Java Archive (.jar) with Jarsigner & Timestamping
jarsigner -tsa http://timestamp.sectigo.com -keystore NONE -storetype PKCS11 app.jar myalias

Ready to Deploy Genuine SSL Certificates?

Browse our comprehensive catalog of DV, OV, and EV certificates from Sectigo, DigiCert, and GeoTrust with instant issuance and 24/7 technical validation support.

0