pkcs11config login --host <tsg-id>.ngts.paloaltonetworks.com --generate
The public key displays on the client screen.
Copy the displayed public key.
Return to the UI. Click Continue. Paste the public key, and then click Finish. The Built-in Accounts inventory page opens.
From the Built-in Accounts inventory page, copy the Client ID for this account.
Return to the Code Sign Client and press Enter.
Paste the Client ID, and then press Enter.
(Optional) Verify your configuration:
pkcs11config option show
Your result should look similar to the following:
INFO: User configuration holds 9 values:
Name │ Value
───────────────────────────────┼───────────────────────────────────────────────────
ACCESS EXPIRES │ 1765225693
AUTHENTICATION PRIVATE KEY PEM │ <365 characters redacted>
HSM SERVER URL │ https://<tsg-id>.ngts.paloaltonetworks.com/vedhsm/
ACCESS TOKEN │ <24 characters redacted>
SUPPORTS API KEY │ true
AUTH SERVER URL │ https://<tsg-id>.ngts.paloaltonetworks.com/
CREDENTIAL EXPIRES │ 1765311162
CSC SERVER URL │ https://<tsg-id>.ngts.paloaltonetworks.com/cyberark-code-sign-client/
CLIENT ID │ xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx