Knowledge Base


How to Enroll a Code Signing Certificate in SCM?
Overview
Code Signing Certificates are used to digitally sign software, ensuring authenticity and integrity. In SCM, enrollment involves creating a certificate profile, setting up an enrollment form, and submitting a Certificate Signing Request (CSR).
Prerequisites
-
Access to Sectigo Certificate Manager (SCM) with administrator privileges.
-
A configured Code Signing Certificate Profile.
-
CSR generated in PEM format.
-
If required, Key Attestation enabled by Sectigo Support.
Step 1: Create a Certificate Profile
-
Log in to SCM as an administrator (MRAO role).
-
Navigate to Enrollment > Certificate Profiles.
-
Click Add to create a new profile.
-
Complete the fields: Name, CA Backend, Certificate Type (Code Signing Certificate), Template (OV or EV), Terms (validity period).
-
Click Save.
Step 2: Delegate Profile to Organization
-
Navigate to Organization > Certificate Settings.
-
Enable Code Signing Certificates.
-
Assign the newly created profile to your organization.
Step 3: Create an Enrollment Form
-
Navigate to Enrollment > Enrollment Forms.
-
Click Add (+) to create a new form.
-
Configure: Type (Code Signing Certificate Enrollment Form), Generate URL Extension, Authentication (Email Confirmation or Secret ID).
-
Click Save.
-
Add the form to an account: Select the form → Accounts → Add (+), provide account details, assign certificate profiles.
Step 4: Send Enrollment Invitation
-
Navigate to Certificates > Code Signing Certificates.
-
Click Invitations → Add (+).
-
Enter: Email of the recipient, Enrollment Endpoint (the form created earlier), Account associated with the endpoint.
-
Click Send.
Step 5: Complete Enrollment
-
The recipient opens the email and clicks the enrollment link.
-
Fill in: Certificate Email (SAN), First Name / Last Name, Certificate Term.
-
Upload: CSR in PEM format, Key Attestation file (if required).
-
Submit the form.
Best Practices
-
Ensure CSR matches the certificate profile requirements.
-
Use strong authentication for enrollment forms.
-
For EV Code Signing, verify organization details before submission.
References
-
Understanding Enrollment Forms: https://docs.sectigo.com/scm/scm-administrator/understanding-enrollment-forms
-
Understanding Certificate Profiles: https://docs.sectigo.com/scm/scm-administrator/understanding-certificate-profiles
-
Understanding Code Signing Certificates: https://docs.sectigo.com/scm/scm-administrator/understanding-code-signing-certificates
-
Managing Code Signing Certificates: https://docs.sectigo.com/scm/scm-administrator/managing-code-signing-certificates
Related Articles:
Tags:
Need help?
Need help making a purchase? Contact us today to get your certificate issued right away.
Live chat
Click the button below or click "Chat with an Expert" to start chatting with us now!