Cloud HSM
If you already run a qualifying hardware security module, generate the code signing key and CSR on the HSM, then order DigiCert OV or EV code signing from GeoCerts with Install on HSM. After issuance, install (merge/import) the certificate onto the same key object.
Do not generate a software CSR. DigiCert will send an HSM attestation email; issuance waits until the requester confirms the key is on certified hardware (FIPS 140-2 Level 2, Common Criteria EAL 4+, or equivalent). Minimum key size is RSA 3072 or ECC P-256.
In this section
Azure Key Vault
Premium tier, RSA-HSM, non-exportable key. Generate a CSR in Key Vault, order with that CSR, merge the issued P7B back into the same certificate object, then sign with AzureSignTool.
AWS CloudHSM
Generate an RSA key pair with CloudHSM CLI, create a CSR with the OpenSSL CloudHSM engine, order with Install on HSM, then bind the issued certificate to that key.
When not to use this path
- You want DigiCert to host the HSM → KeyLocker
- You want a shipped USB token → USB eToken