Cloud HSM

If you already run a qualifying hardware security module, generate the code signing key and CSR on the HSM, then order DigiCert OV or EV code signing from GeoCerts with Install on HSM. After issuance, install (merge/import) the certificate onto the same key object.

Do not generate a software CSR. DigiCert will send an HSM attestation email; issuance waits until the requester confirms the key is on certified hardware (FIPS 140-2 Level 2, Common Criteria EAL 4+, or equivalent). Minimum key size is RSA 3072 or ECC P-256.


In this section

Azure Key Vault

Premium tier, RSA-HSM, non-exportable key. Generate a CSR in Key Vault, order with that CSR, merge the issued P7B back into the same certificate object, then sign with AzureSignTool.

Azure Key Vault »

AWS CloudHSM

Generate an RSA key pair with CloudHSM CLI, create a CSR with the OpenSSL CloudHSM engine, order with Install on HSM, then bind the issued certificate to that key.

AWS CloudHSM »


When not to use this path


← Back to Code Signing