DigiCert KeyLocker

DigiCert KeyLocker is DigiCert’s cloud HSM for code signing private keys. Keys are generated and stored in FIPS 140-2 Level 3 hardware. You do not wait for a USB token and you do not operate your own HSM.

GeoCerts offers KeyLocker as a provisioning method on DigiCert OV and EV code signing orders. Sign from anywhere and plug signing into CI/CD without shipping hardware.


When to use KeyLocker

Choose KeyLocker if you:

  • Do not want a physical eToken (loss, shipping delay, single workstation)
  • Need several people or pipelines to sign without passing a USB stick
  • Want DigiCert to host the HSM instead of Azure Key Vault or AWS CloudHSM

Stay on a USB eToken or your own HSM if your process requires an air-gapped signer, you already standardized on Azure/AWS HSM, or you do not want DigiCert ONE / KeyLocker in the signing path.

Compare methods: Choose a provisioning method.


Order with KeyLocker through GeoCerts

  1. Log in to CertCommand and start an OV or EV code signing order.
  2. Select KeyLocker as the provisioning method. No CSR is required.
  3. Complete validation. After issuance, DigiCert provisions the private key in KeyLocker and typically creates or enables a DigiCert ONE account with KeyLocker for the requester.
  4. Sign in to DigiCert ONE and open KeyLocker to confirm the certificate and key.

If KeyLocker is not listed on the order form, contact GeoCerts support—it may need to be enabled for your account or product.


Signing and CI/CD

This GeoCerts page covers ordering and access. For client install, API keys, smctl, and pipeline examples, use DigiCert’s KeyLocker documentation—do not duplicate that book here.

DigiCert KeyLocker documentation

Start with DigiCert’s Get started and signing client guides after you can see the certificate in DigiCert ONE.

For workstation signing without KeyLocker, see Sign your code.


Reissue

Reissue in CertCommand the same way as other DigiCert CS products. Keep KeyLocker as the provisioning method unless you are intentionally moving to a token or HSM (that creates a new key).

See Order a code signing certificate.


← Back to Code Signing