← Back to homepage

Trust services

Code Signing — sign your software before it reaches users

I explain which Code Signing certificate fits, guide you through verification and help organise the signing process for application releases.

What it is

A signature shows who issued a file — and whether it changed after signing

A Code Signing certificate digitally signs code or a release file. The recipient can verify the publisher’s identity and the integrity of the signed file.

  • Publisher identity
    A user and operating system can verify who signed an application or installer.
  • File integrity
    Changing a file after signing makes its signature invalid.

What it signs

Not only .exe files

Applications

Windows applications and EXE or MSI installers issued to users or partners.

Components

DLL libraries and other files that form part of a software release.

Automation

PowerShell scripts used in company environments and deployment processes.

Systems

Drivers and other files for which publisher confirmation matters.

Developer questions

What Code Signing does not solve on its own

Does signing make an application secure?

It does not replace testing, code review, dependency updates or a protected release process. It confirms the publisher and helps detect changes to a signed file.

Does signing always remove Windows warnings?

That cannot be guaranteed. Messages depend on system protections, application reputation and the distribution method, among other factors.

Is Code Signing the same as SSL?

No. SSL secures a connection to a domain or online service. Code Signing signs an application, installer, script or another file.

Choosing an option

Standard, EV or Open Source? First I establish who publishes the code and how

Certum offers Open Source, Standard and EV options. They differ in intended use and the scope of entity validation.

I do not start with the most expensive option. First, I check who publishes the application, who it is for and how the team organises releases.

I do not publish fixed prices or promised issuance times; these depend on the current offer and verification situation.

Signing continuity

A shorter certificate lifetime needs a plan for future releases

Industry standards shorten the lifetime of individual Code Signing certificates. I therefore establish not only the right certificate option, but also renewal and continuity for signing future releases.

For a team and CI/CD pipeline, it is worth defining the process owner, certificate replacement timing and secure key access in advance. Timestamping remains important for continued verification of files signed earlier.

Key and timestamping

The most important element is not visible to the user

A certificate should not be treated as an ordinary file to pass between computers. We establish who signs releases, where the process runs and how to limit access to the private key.

I also explain timestamping: it confirms the time of signing and matters when a signature is verified after the certificate’s validity period ends.

How I guide the setup

From release scenario to a signed file

01

I understand the scenario

I establish what you sign, who publishes the application and how releases currently work.

02

I choose the option

I explain the differences between options and validation requirements.

03

I guide verification

I help assemble the information and documents required to issue the certificate.

04

We plan activation

I explain a safe way to begin signing, including the role of the private key and timestamping.

Contact

Before buying a certificate, describe how you release your application

Tell me which files you sign, who the publisher is and how releases work. We will establish the right option and activation approach.

info@mnet.com.pl