DigiCert KeyLocker
DigiCert KeyLocker is DigiCert’s cloud HSM for code signing private keys. Keys are generated and stored in FIPS 140-2 Level 3 hardware. You do not wait for a USB token and you do not operate your own HSM.
GeoCerts offers KeyLocker as a provisioning method on DigiCert OV and EV code signing orders. Sign from anywhere and plug signing into CI/CD without shipping hardware.
459-day maximum validity. Newly issued public code signing certificates cannot exceed 459 days (DigiCert’s implementation of the CA/Browser Forum’s 460-day cap). Multi-year product terms may still be sold, but you must reissue during the term. See Change Log — 459-day CS validity.
When to use KeyLocker
Choose KeyLocker if you:
- Do not want a physical eToken (loss, shipping delay, single workstation)
- Need several people or pipelines to sign without passing a USB stick
- Want DigiCert to host the HSM instead of Azure Key Vault or AWS CloudHSM
Stay on a USB eToken or your own HSM if your process requires an air-gapped signer, you already standardized on Azure/AWS HSM, or you do not want DigiCert ONE / KeyLocker in the signing path.
Compare methods: Choose a provisioning method.
Order with KeyLocker through GeoCerts
- Log in to CertCommand and start an OV or EV code signing order.
- Select KeyLocker as the provisioning method. No CSR is required.
- Complete validation. After issuance, DigiCert provisions the private key in KeyLocker and typically creates or enables a DigiCert ONE account with KeyLocker for the requester.
- Sign in to DigiCert ONE and open KeyLocker to confirm the certificate and key.
If KeyLocker is not listed on the order form, contact GeoCerts support—it may need to be enabled for your account or product.
Signatures. DigiCert documents an initial KeyLocker signature allowance on order or renewal (commonly 1,000 signatures). Additional signatures are purchased from DigiCert. Token and self-managed HSM provisioning do not use this meter.
Signing and CI/CD
This GeoCerts page covers ordering and access. For client install, API keys, smctl, and pipeline examples, use DigiCert’s KeyLocker documentation—do not duplicate that book here.
DigiCert KeyLocker documentation
Start with DigiCert’s Get started and signing client guides after you can see the certificate in DigiCert ONE.
For workstation signing without KeyLocker, see Sign your code.
Reissue
Reissue in CertCommand the same way as other DigiCert CS products. Keep KeyLocker as the provisioning method unless you are intentionally moving to a token or HSM (that creates a new key).
See Order a code signing certificate.