Applications
Windows applications and EXE or MSI installers issued to users or partners.
Trust services
I explain which Code Signing certificate fits, guide you through verification and help organise the signing process for application releases.
What it is
A Code Signing certificate digitally signs code or a release file. The recipient can verify the publisher’s identity and the integrity of the signed file.
What it signs
Windows applications and EXE or MSI installers issued to users or partners.
DLL libraries and other files that form part of a software release.
PowerShell scripts used in company environments and deployment processes.
Drivers and other files for which publisher confirmation matters.
Developer questions
It does not replace testing, code review, dependency updates or a protected release process. It confirms the publisher and helps detect changes to a signed file.
That cannot be guaranteed. Messages depend on system protections, application reputation and the distribution method, among other factors.
No. SSL secures a connection to a domain or online service. Code Signing signs an application, installer, script or another file.
Choosing an option
Certum offers Open Source, Standard and EV options. They differ in intended use and the scope of entity validation.
I do not start with the most expensive option. First, I check who publishes the application, who it is for and how the team organises releases.
I do not publish fixed prices or promised issuance times; these depend on the current offer and verification situation.
Signing continuity
Industry standards shorten the lifetime of individual Code Signing certificates. I therefore establish not only the right certificate option, but also renewal and continuity for signing future releases.
For a team and CI/CD pipeline, it is worth defining the process owner, certificate replacement timing and secure key access in advance. Timestamping remains important for continued verification of files signed earlier.
Key and timestamping
A certificate should not be treated as an ordinary file to pass between computers. We establish who signs releases, where the process runs and how to limit access to the private key.
I also explain timestamping: it confirms the time of signing and matters when a signature is verified after the certificate’s validity period ends.
How I guide the setup
I establish what you sign, who publishes the application and how releases currently work.
I explain the differences between options and validation requirements.
I help assemble the information and documents required to issue the certificate.
I explain a safe way to begin signing, including the role of the private key and timestamping.
Contact
Tell me which files you sign, who the publisher is and how releases work. We will establish the right option and activation approach.
info@mnet.com.pl