Signing Manager Controller (SMCTL) provides a Command Line Interface (CLI) that facilitates manual and automated private key management, certificate management, and signing with or without the need for human intervention.
SMCTL comes with a built-in help function and provides instructions on all commands and subcommands to assist users in the CTL tool. See SMCTL command manual.
SMCTL provides secure key generation, application hash signing, and associated certificate-related requirements when the signing request does not require the transportation of files and intellectual property.
To view all SMCTL commands:
smctl --help
or
smctl -h
These subcommands specify the actions you can apply to commands when using SMCTL.
All SMCTL commands begin with:
smctl <subcommand>
Shortcut | Subcommand | Description |
---|---|---|
cert | Manage certificates. | |
creds | Manage credentials for the OS credential store. | |
Manage GPG keypairs and keyrings. | ||
View and confirm the validity of the credentials and tools configured. | ||
Manage HSMs mapped to your Software Trust Manager account. | ||
kp | Manage keypairs. | |
Manage logs. | ||
manual | Generates up-to-date man pages of Signing Manager’s command-line interface. By default, it creates the man page files in the man-pages directory under the current directory. | |
Manage notarizations for Apple binaries. This command is only available on macOS. | ||
rel | Manage releases. | |
sc | Manage scans powered by ReversingLabs. | |
Sign, verify, or remove a signature from binaries, hashes, and SBOMs. | ||
Get user data. | ||
Commands specific to Windows OS. |
Flags are used to modify the behavior of a subcommand by specifying parameters. Apply these flags to the subcommands above when using SMCTL.
Shortcut | Flag | Description |
---|---|---|
-v | --version | Version of SMCTL. |
--dir string | Specify the directory to write the man pages. Default is man-pages/. Format: --dir="<value>" | |
-h | --help | Help for SMCTL. |
SMCTL integrates with and enables secure hash-based signing with the following signing tools while maintaining key protection, permission-based access and reporting all signing activities:
Sign in to DigiCert ONE.
Navigate to DigiCert® Software Trust Manager > Resources > Client tool repository.
Select your operating system.
Click the download icon next to Signing Manager Controller (SMCTL).
Follow the instructions in one of the following articles based on the operating system you will use to sign:
To verify that your client can properly authenticate to the DigiCert® Software Trust Manager service:
Open smctl.exe.
Run:
smctl healthcheck
Review the following table to understand how to obtain the latest version of SMCTL and other client tools:
SMCTL or client tools | Sample command |
---|---|
SMCTL (with auth) | |
SMCTL (without auth) | |
JCE | |