Knowledge Base


What is the key attestation for Code Signing?
Similar Questions:
How does Key Attestation work in Sectigo SCM?
How do I set up Code Signing Certificates with Key Attestation in Sectigo SCM?
What steps are needed to create a Code Signing Certificate with Key Attestation?
How to create code signing certificates with key attestation in Sectigo SCM?
Overview:
This document describes the steps needed to produce Code Signing certificates with Key Attestation in the Sectigo Certificate Management platform.
This step-by-step guide covers the steps for:
i) Creating the Certificate Profile
ii) Enrollment form
iii) Submitting the certificate with Key Attestation via the form.
Steps to follow:
Creating the Assets in SCM:
A) Create a Code Signing Certificate Profile.
-
Choose “Code Signing Certificate” as the “Certificate Type”:
-
Choose a CA Backend that supports code signing with Key Attestation:
-
Choose a Certificate Template having Key Attestation:
-
Assign terms:
B) Create a Code Signing Enrollment form:
-
Ensure the type is “Code Signing Certificate Enrollment Form”:
-
Generate a URL extension:
-
Save
Add the Enrollment form to an account
-
Select the Enrollment form and click the “Account” option:
-
Click to add the new account:
-
Configure the Organization Department Profile
C) Submitting the CSR with Attestation via Enrollment Form
Send an invite to the user who will be sending the CSR & Attestation
-
Access “Certificates” > “Code Signing Certificates” from SCM:
-
Click “Invitations” from the top-right corner:
-
Click the “+” Icon:
-
Enter the following:
-
Email (Email of the recipient who will provide the CSR & Attestation
-
Enrollment Endpoint (The Enrollment form to be used)
-
Account (This should populate based on the selected Enrollment endpoint, in case it does not, select the Account having the key attestation template)
-
Click the “Send” control:
D) Submitting the CSR with Attestation:
-
The recipient needs to open the email they received from the enrollment form:
-
The recipient will need to enter:
-
The Certificate Term:
-
The “Certificate Email” (San)
-
First Name
-
Last Name
-
The recipient will need to upload the CSR
-
The recipient will need to add the Key Attestation
-
The value:
-
The HSM Type:
-
Any mandatory Custom fields will need to be entered.
-
The user must accept the EULA
-
Submit the enrollment
Related Articles:
Tags:
Need help?
Need help making a purchase? Contact us today to get your certificate issued right away.
Live chat
Click the button below or click "Chat with an Expert" to start chatting with us now!