告别手动运维:锐安信CLM重磅发布,开启SSL证书自动化运维新时代
锐成信息联合Sectigo共同举办了「CLM – SSL证书自动化运维解决方案发布会」,重磅发布了专为中大型企业与复杂网络环境设计的SSL证书自动化运维系统——锐安信CLM。
The sslTrus sslTrus code signing certificate based on the global root of trust can clearly identify the true identity of the software or code developer, and at the same time ensure that the software is not maliciously tampered with after signing. Comprehensively enhance the security and credibility of the software to help you establish an outstanding reputation for your software brand.
import { Security } from '@ssltrus/core';
const app = new Software({
name: "Racent_Enterprise_App.exe",
publisher: "Racent Information Tech"
});
app.signCode();
Precisely matching the development needs of enterprises, it offers dual options of basic identity verification and financial-grade hardware protection.
It provides standard identity verification, with short processing time and low cost. However, it is not applicable to LSA/UEFI signatures and kernel-mode driver signatures.
It includes all the functions at the basic level, with higher security (key stored on the token), and supports driver signature, SmartScreen green card and WHQL authentication.
Unsigned software applications may trigger system security warnings and display "Unknown Publisher". This not only affects the user experience but may also lead to user churn due to security concerns.
When using a code signing certificate, the information of the publisher will be directly displayed during software installation. This enhances user trust from the source, eliminates security concerns, provides a smooth experience, and helps increase download volumes.
Policy Adjustment: Due to significant changes in Microsoft's kernel-level security policy, it is now necessary to strictly obtain valid digital signatures for drivers through the WHQL logo certification scheme. The sslTrus Enterprise Edition EV certificate supports driver signature mode and WHQL logo certification scheme, helping you cope with compatibility adaptation adjustments.
OV can be issued after verifying the enterprise identity, offering cost-effectiveness. EV verification is more rigorous and the private key is forcibly stored in the hardware device, which is the prerequisite for the kernel driver signature and WHQL logo authentication. In Microsoft's SmartScreen reputation algorithm, the weight of EV is higher. The download volume required to accumulate reputation is much less than that of OV. For newly released software, it is recommended to give priority to choosing EV.
Microsoft has adjusted the SmartScreen reputation assessment mechanism: it no longer allows users to pass based solely on the type of certificate, but instead makes a comprehensive judgment based on software download volume and user trust. Newly released software may trigger warnings regardless of whether it uses EV or OV certificates, and these warnings will gradually disappear as the download volume accumulates. This is a control behavior of Microsoft rather than an issue with the certificates themselves.
Supports. exe,. dll,. msi,. cab,. ocx,. sys drivers and ActiveX controls. It is also applicable to various code and installation package formats such as Java programs, Office macros, PowerShell scripts, Adobe AIR, etc., covering mainstream software distribution scenarios.
It is strongly recommended that a trusted timestamp be attached to each signature. The timestamp can prove that the signing behavior occurred during the validity period of the certificate. Even if the certificate expires in the future, the signature of the released software remains valid for a long time and will not pop up a new security warning due to the expiration of the certificate.
Software with timestamps added during signature is not affected, and the signature remains permanently valid. Software without a timestamp will be re-prompted by the system as unknown to the publisher after the certificate expires. Therefore, it is essential to configure the timestamp server in the signature tool. Once configured, it will bring long-term benefits.
From SSL/TLS certificate discovery, enrollment and deployment to continuous monitoring, alerting and automatic renewal, sslTrus helps enterprises build a unified certificate automation platform—reducing the operational burden of growing certificate inventories and shorter validity periods.
Certificates Meet the Latest Security Baseline
Encrypt and sign enterprise email to prevent phishing, tampering and interception.
Trusted certificates secure applications, servers, gateways and websites with HTTPS.
A lightweight, cloud-native subscription model that enables agile, automated deployment across public clouds and business nodes.
Scale signing with cloud HSM protection while keeping private keys secure.
Deploy a highly available PKI for internal systems, users and connected devices.
Discover, monitor, deploy and renew certificates across your environment—automatically. Prevent outages caused by missed renewals.
Explore sslTrus updates, security trends and in-depth technical guidance.