Secure Your Code
Digitally sign your code to increase user trust and download rates
- Remove unknown publisher security warnings
- Protects software from tampering and malware injection
- Sign Authenticode, Office VBA, Adobe AIR, Mozilla, Mac OS
Start Securing Your Code
You need a Code Signing Certificate to digitally sign your code. Pricing depends on the level of verification and the amount of information contained in the certificate.
Please note: GlobalSign code signing certificates can be issued in the name of a legally registered organization only.
Standard Code Signing
- Compatible with major platforms
- Company identity in certificate
- Removes "unknown publisher"
- Security Warnings
Token Implementation
- Key storage on USB token or other hardware storage token
HSM Implementation
- Key storage on HSM or Azure Key Vault, provided by customer
Extended Validation (EV) Code Signing
- All features of standard Code Signing
- Company name, address, and type included in certificate
- Supports registration for Windows Hardware Developer Center
Token Implementation
- Key storage on USB token, provided by GlobalSign
HSM Implementation
- Key storage on HSM or Azure Key Vault, provided by customer
Standard Code Signing Certificates | Extended Validation (EV) Code Signing Certificates | |
---|---|---|
Certificate Features | ||
Information displayed in Certificate | Organization Name | Organization Name Organization address Type of Organization |
Removes "unknown publisher" security warnings | ||
Signature does not expire when Time Stamping is applied | Time stamping available & recommended | Time stamping available & recommended |
Sign an unlimited number of applications | ||
Compatible with major platforms (Authenticode, Office VBA, Java, Adobe AIR. Mac OS, Mozilla) | ||
Key storage options | You have a choice of storing keys on a token or HSM. Tokens are included in our package, HSM is not provided. Token options (choose “Token Implementation” at checkout) - Cryptographic USB token - Other hardware storage token - SD card or USB token HSM options (choose “HSM Implementation” at checkout) - HSM - Azure Key Vault |
By default, a cryptographic USB token is included with EV Code Signing Certificates. If you’d prefer, EV Code Signing Certificates can be stored on an HSM or Azure Key Vault (provided by customer). Please select the “HSM Implementation” option at checkout. |
Pricing | ||
1 Year | • | • |
2 Year | • | • |
3 Year | • | • |
Token Implementation |
|
|
HSM Implementation |
|
|
*GlobalSign allows standard and EV Code Signing Certificates to be installed on customer HSMs or in Azure Key Vault. Contact us for more information about these deployment options.
^USB token not included in HSM or Key Vault deployments.
Please ensure to order your certificate from the Region where the company in the certificate is based, and with the correct currency. If your certificate request upon ordering does not match these criteria, your order may risk being delayed, and/or not being processed.
Select RegionWhat are the Key Storage Options for Code Signing Certificates?
As a substantial increase in Software Supply Chain (SSC) attacks and use of open-source software is observed in recent years, GlobalSign understands heightened concerns around securing codes and code signing process at your company. Whether it’s a SSC attack or other, we can help you protecting your private keys against malicious party by executing compliance with industry standards which require the strongest key protection possible, i.e. FIPS 140 Level 2 or Common Criteria EAL 4+ compliant. Proper handling of private keys not only minimizes the risk of fraudulent access to the keys, but also allows for easier trace at the time of forensic investigation.
Storing the keys on secure cryptographic hardware, such as a USB token or Hardware Security Module compliant with the standards, significantly decreases the chance of key compromise compared to storing the keys locally or substandard equivalents for easier internal sharing. Therefore, now it’s a requirement for both standard Code Signing and Extended Validation Code Signing Certificates. Both GlobalSign standard Code Signing Certificates and GlobalSign EV Code Signing Certificates are automatically shipped with a standards-compliant cryptographic USB token, unless HSM implementation option is selected at checkout.
If you or your company currently utilize a hardware security module (HSM) such as Azure Key Vault, you have the option to select that implementation when purchasing either standard or EV code signing certificates
Why should you digitally sign your code?
Code Signing Certificates are used by developers on all platforms to digitally sign the applications and software they distribute over the Internet. Code Signing essentially provides the same assurance as a shrink wrapped CD – the signed code includes the name of the publisher and assurance that the code hasn't been tampered with since being published. Anyone downloading software off of the internet can make a decision whether or not to trust the software.