Code signing certificate

sslTrus Code Signing Certificate

The sslTrus sslTrus code signing certificate based on the global root of trust can clearly identify the true identity of the software or code developer, and at the same time ensure that the software is not maliciously tampered with after signing. Comprehensively enhance the security and credibility of the software to help you establish an outstanding reputation for your software brand.

import { Security } from '@ssltrus/core';

const app = new Software({

  name: "Racent_Enterprise_App.exe",

  publisher: "Racent Information Tech"

});

app.signCode();

EV Signature Verified
sslTrus Code Signing Certificate

Precisely matching the development needs of enterprises, it offers dual options of basic identity verification and financial-grade hardware protection.

Basic Version

Ordinary Code signing Certificate

It provides standard identity verification, with short processing time and low cost. However, it is not applicable to LSA/UEFI signatures and kernel-mode driver signatures.

¥3700Since /
  • Fast issuance within 1 to 3 working days
  • Application standard signature
  • Organizational Enterprise Identity Authentication (OV)
  • RSA 2048/3072/4096 & ECC
  • 7* 24-hour expert service
  • 30-day worry-free refund plan
Apply Now

The deployment effect is clear at a glance with mouse Hover.

> verifying code signature...
> ERR_UNKNOWN_PUBLISHER
Installation blocked by Windows SmartScreen. Potential security risk.
> verifying code signature...
> OK_PUBLISHER_VERIFIED
Identity: Racent Tech.
Certificate: EV Code Signing.
Not EV code signed

Frequent appearance of "unknown publishers" can easily lead to loss of trust.

Unsigned software applications may trigger system security warnings and display "Unknown Publisher". This not only affects the user experience but may also lead to user churn due to security concerns.

EV code signed

Protecting trust and enhancing software acceptance

When using a code signing certificate, the information of the publisher will be directly displayed during software installation. This enhances user trust from the source, eliminates security concerns, provides a smooth experience, and helps increase download volumes.

Core advantages of sslTrus code signing

Prevent malicious tampering

Eliminate safety warnings

Make software trustworthy

Enhance brand image

Identify the developer's identity

Support multiple platforms

Selection of WHQL Microlabel Authentication Driver Signature

Policy Adjustment: Due to significant changes in Microsoft's kernel-level security policy, it is now necessary to strictly obtain valid digital signatures for drivers through the WHQL logo certification scheme. The sslTrus Enterprise Edition EV certificate supports driver signature mode and WHQL logo certification scheme, helping you cope with compatibility adaptation adjustments.

Visit racent.com to purchase a code signing certificate online.

Frequently Asked Questions

How to choose between EV and OV code signing certificates?

OV can be issued after verifying the enterprise identity, offering cost-effectiveness. EV verification is more rigorous and the private key is forcibly stored in the hardware device, which is the prerequisite for the kernel driver signature and WHQL logo authentication. In Microsoft's SmartScreen reputation algorithm, the weight of EV is higher. The download volume required to accumulate reputation is much less than that of OV. For newly released software, it is recommended to give priority to choosing EV.

Why does code signing still prompt "Unknown Publisher" or indicate insecurity?

Microsoft has adjusted the SmartScreen reputation assessment mechanism: it no longer allows users to pass based solely on the type of certificate, but instead makes a comprehensive judgment based on software download volume and user trust. Newly released software may trigger warnings regardless of whether it uses EV or OV certificates, and these warnings will gradually disappear as the download volume accumulates. This is a control behavior of Microsoft rather than an issue with the certificates themselves.

Which file formats are supported by code signing certificates?

Supports. exe,. dll,. msi,. cab,. ocx,. sys drivers and ActiveX controls. It is also applicable to various code and installation package formats such as Java programs, Office macros, PowerShell scripts, Adobe AIR, etc., covering mainstream software distribution scenarios.

What is the function of a timestamp? Must it be added when signing?

It is strongly recommended that a trusted timestamp be attached to each signature. The timestamp can prove that the signing behavior occurred during the validity period of the certificate. Even if the certificate expires in the future, the signature of the released software remains valid for a long time and will not pop up a new security warning due to the expiration of the certificate.

Will the signed software become invalid after the certificate expires?

Software with timestamps added during signature is not affected, and the signature remains permanently valid. Software without a timestamp will be re-prompted by the system as unknown to the publisher after the certificate expires. Therefore, it is essential to configure the timestamp server in the signature tool. Once configured, it will bring long-term benefits.

From Manual Certificate Operations to Automation

From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.

  • Overview
  • Certificate Requests
  • Certificate Deployment
  • Discovery Agents
  • Compliance & Alerts
  • Settings
Global Overview
Total Certificates
12,458
Pending
34
Expiring in 30 Days
15
Expired
2
Automated Deployments · 30 Days
Expiration Risk · Next 6 Months
Overall Compliance Rate
96%

Certificates Meet the Latest Security Baseline

Device & Cloud Asset Mix
Alibaba Cloud (40%)
AWS (25%)
Azure (15%)
F5 (10%)
Cisco (10%)