Menu
picture of tbs certificates
picture of tbs certificates
Certificates
Our products range
Partners
Support
Focus


20220808 - End of Code Signing certificates in software format

From June 1st, 2023 the Authorities won't be able to issue OV code signing certificates in software format anymore. These products will have to be installed and delivered on a secure HCM (Hardware Crypto Module).

Why?

The CA/B Forum took this decision in order to enhance the security level of these products.

The use of a secure module is a guarantee that the private key is generated, stored, and used in a secure environment that can only be accessed via a password. Since the private key cannot be extracted from its secure module, one has to get access to the module and the associated password to use it.

The Hardware Crypto Module will have to comply to at least FIPS 140‐2 level 2 or Common Criteria EAL 4+ standards.

What about the currently valid certificates?

Currently valid certificates will keep working properly until their expiration date.

The reissuances requested after the deadline will also have to be delivered on a secure crypto module and will be handled on a case-by-case basis.

Note that since 2017 it is strongly recommended to store your code signing certificates on a secure crypto module. Consult our online documentation on the subject.

Which products are impacted?

All Sectigo and DigiCert OV (Organization Validation) code signing certificates will be impacted. Ev code signing certificate must already be stored on secure crypto modules.

Note: Sectigo is taking a lead and will cease issuing code signing certificates in software format on May 8, 2023 and won't accept new order as of April 21, 2023 at 5pm.

The DigiCert OV Code Signing certificates in software format will disappear on March 21, 2023.

What consequences for those products?

The price of Sectigo code signing certificate will undergo a raise to cover the secure module purchase and delivery.

If you still have available tokens on May 8, 2023, an exchange will have to be done on a case-by-case basis.

The DigiCert group has not planned to raise its prices for the time being. The available tokens can be used for any new order.

What about orders not delivered on the deadline?

Non delivered orders will have to be canceled and replaced by new ones. The new products won't be handled the same way technically and new orders will have to be sent to the authorities.

Important: If you need to obtain OV code signing certificates in software format then you should order them before April 21, 2023 for Sectigo.

A promotional code is available for any order of an OV code signing certificate valid 3-years placed before April 21, 2023 for Sectigo or before May 21, 2023 for DigiCert. During your order deposit enter the following code in the form:

ProlongDevOV2023

or use the following link:

Useful links