Knowledge Base

Why Sectigo Signing Certificate Orders (Code Signing, Document Signing, eIDAS) Use Hardware-Protected Keys

Overview 

Use this article to understand the difference between a certificate and its private key, the purpose and limits of hardware protection, and how to plan for token-based signing. 

Applies to 

Sectigo orders supplied with a SafeNet Universal Serial Bus (USB) token for Organization Validation (OV) Code Signing, Extended Validation (EV) Code Signing, Document Signing, Ensured Document Signing, and applicable electronic identification, authentication and trust services (eIDAS) products. 

Why protect the private key? 

A digital signature is created using a private key; the corresponding public certificate supports verification of that signature. 

A private key stored as an exportable file may be copied through unauthorized access to the computer, backups, or storage containing it. 

In the token-based provisioning described here, the private key is generated on the token and remains nonexportable, while signing operations take place within the device. 

This helps protect the key against extraction and duplication. 

A certificate is not its private key 

The public certificate and private key have different purposes: 

  • Public certificate: Provides information used to verify signatures. 

  • Private key: Enables signing and must remain protected. 

Downloading or exporting a public certificate is not the same as exporting its private key. 

A .pfx file can contain a certificate and its associated private key; a nonexportable token-held key cannot be copied into such a file. 

Hardware protection does not always mean a USB token 

The original provisioning guidance identifies physical tokens, hardware security modules (HSMs), and some cloud-based signing options as hardware-protected approaches. 

The permitted configuration depends on the product, applicable requirements, and available service. 

Code signing 

The CA/Browser Forum’s code-signing requirements are identified as a source of private-key protection requirements for publicly trusted code-signing certificates. 

Do not interpret hardware protection as a universal requirement to receive a physical USB token: the provisioning guidance also identifies HSM-based alternatives. 

Confirm the current requirements and supported configuration for your specific order. 

Document signing 

The Document Signing and Ensured Document Signing orders covered by this article use token-based protection for their signing keys. 

Hardware protects the key; it should not be described as independently guaranteeing document integrity, signer identity, or long-term signature validity. 

eIDAS products 

The provisioning guidance identifies qualified signature creation devices (QSCDs) in its discussion of eIDAS products. 

Confirm the certificate’s intended signing or sealing use, the applicable qualification requirements, and the supported device or service with a Sectigo specialist. 

Do not assume that possession of an eIDAS certificate or a physical token alone establishes the legal status of a resulting signature or seal. 

What hardware protection does—and does not—provide 

Protects against key copying: A nonexportable token key is not available as an ordinary file for copying or backup. 

Performs signing within the device: The token performs the signing operation without exporting the private key. 

Provides device-level controls: The provisioning guidance describes resistance to physical tampering and lockout after repeated incorrect password attempts. 

Does not eliminate every threat: Protect the signing computer, restrict token access, and safeguard credentials; key protection should not be presented as complete protection against unauthorized signing. 

Does not prove personal authorization: A valid signature should not, by itself, be described as conclusive proof that a particular individual personally approved the signing operation. 

What this means in practice 

Plan for delivery and signing access 

If your order includes a shipped token, allow time for delivery and use the tracking information in your shipment notification. 

Plan how the signing system will access the token before scheduling signing work. 

Check remote-access compatibility 

Do not assume that every remote-access environment behaves identically. 

For Windows token-detection issues, consult Troubleshoot a SafeNet USB token not detected on Windows. 

Do not treat a second token as a private-key backup 

The token-held private key cannot be exported to create a duplicate signing token. 

If you need signing capability in multiple locations, discuss an additional certificate or supported cloud-based option with Sectigo. 

Get help with lost, damaged, or locked tokens 

Contact Sectigo Support to determine the recovery, replacement, or reissuance options for your order rather than assuming a particular outcome or fee. 

Do not reinitialize a provisioned token as a troubleshooting step; reinitialization can destroy its stored certificate and private key. 

Is there an alternative to a physical token? 

Some products support cloud-based or HSM-backed signing without shipping a device; contact Sectigo Sales to discuss availability for your product and region. 

Related articles 

Need help? 

  • United States: +1 (888) 266-6361 

  • International: +1 (703) 581-6361. 

 

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today