Order a code signing certificate

Place DigiCert OV or EV code signing orders in CertCommand. The steps below assume you already chose a provisioning method.


Order in CertCommand

  1. Log in to CertCommand and click New Certificate.
  2. Choose OV Code Signing or EV Code Signing.
  3. Select the provisioning method:
    • DigiCert-provided hardware token — no CSR; DigiCert ships an eToken.
    • KeyLocker — no CSR; DigiCert provisions the key in KeyLocker.
    • Install on HSM (Azure Key Vault, AWS CloudHSM, or other approved HSM) — paste the CSR generated on that HSM.
  4. Complete organization details (and EV identity information if applicable).
  5. Submit the order and watch email for validation requests.

Validation

OV requires organization validation. EV adds individual identity verification and typically takes additional business days.

Reuse periods for organization validation can change with CA/Browser Forum rules. If validation is expired, DigiCert must revalidate before issuing or reissuing. See the Change Log for current reuse timelines.


After issuance

Provisioning What you do next
USB eToken When the token arrives, confirm receipt in CertCommand, copy the initialization code, and install the certificate on the eToken.
KeyLocker Access the certificate in DigiCert ONE / KeyLocker. See DigiCert KeyLocker.
Azure Key Vault Download the certificate (prefer PKCS #7 / .p7b) and merge it into the same Key Vault cert object.
AWS CloudHSM Download PEM or P7B and bind it to the CloudHSM key that generated the CSR.

Reissue and multi-year terms

Multi-year product terms may still be sold, but each issued certificate is capped near 460 days. Plan a reissue before the current certificate expires—not a brand-new order—unless you are changing organization details or provisioning method.

To reissue:

  1. In CertCommand, open the order.
  2. Choose Order Actions → Reissue Certificate.
  3. Keep the same provisioning method unless you intend to generate a new key (new token init, new HSM CSR, or new KeyLocker key).
  4. If Reissue Certificate is greyed out, contact GeoCerts support.

CertCommand Order Actions menu with Reissue Certificate highlighted

For a locked or wiped eToken, reissue and then re-install. See Passwords, lockouts, and reissue.


← Back to Get Started