Configuring the Code Signing Capability
Focus
Focus
Next‑Gen Trust Security

Configuring the Code Signing Capability

Table of Contents

Configuring the Code Signing Capability

The topics in this section walk you through the steps required to configure the code signing capability for use in your environment.
If you have not yet reviewed the conceptual material or completed the tutorial, consider starting with:
  • Solution overview — Learn how the code signing capability works and how the core components fit together.
  • Tutorial — Follow a guided workflow to see the full signing lifecycle in action.
Once you are ready to configure your environment directly, use the table below to determine which setup tasks you need to complete.

Setup Tasks at a Glance

TaskWho performs itRequired?When you need it
Onboard usersTSG administratorAlwaysBefore any user can manage or use Signing Keys.
Create a built-in accountUser with write access to Built-in Accounts pageAlwaysRequired to authenticate the Code Sign Client on a signing machine.
Configure a CAUser with write access to Signing Keys pageOptionalRequired only if you plan to issue certificates from Microsoft AD CS, DigiCert, or Zero Touch PKI. Not required for “None” or “Built-in CA.”
Create a Signing KeyUser with write access to Signing Keys pageAlwaysRequired to generate the keys and certificates used for signing.
Install and authenticate Code Sign ClientSigner or CI operatorAlways (to sign)Must be completed on any signing machine before authentication or signing can occur.