Skip to main content

DigiCert KeyLocker

Release notes RSS

Recent releases

September 3, 2025

DigiCert® ONE version: 1.10937.1 | KeyLocker: 1.1087.0

Fixes

Fixed signer update error

We resolved an issue where users received a Error parsing JSON object error when attempting to change the signer to themselves. Users can now successfully update the signer without encountering this error.

August 14, 2025

DigiCert® ONE version: Not applicable | DigiCert KeyLocker: Not applicable

Included in this release:

New

Action required: Add new DigiCert ONE clientauth IP addresses

On September 12, 2025, at 10:00 MDT (16:00 UTC), DigiCert will add new IP addresses for inbound requests using the Client authentication endpoint (clientauth.one.digicert.com).

To ensure proper connectivity for your client tools, you or your customers need to add the following IP addresses to applicable allowlists and firewall rules:

1.

Classification

URL

IP addresses

Client authentication endpoint

clientauth.one.digicert.com

  • 216.168.244.38 (CURRENT)*

  • 216.168.244.56 (NEW)

  • 216.168.240.32 (NEW)


참고

*The current Client authentication IP address will remain active and should not be removed.

August 6, 2025

DigiCert® ONE version: 1.10789.1 | DigiCert KeyLocker: 1.1080.0

Included in this release:

Fixes

July 30, 2025

DigiCert® ONE version: 1.10498.15 | DigiCert KeyLocker: 1.1075.0

Included in this release:

Enhancements

Style changes to DigiCert ONE

In the DigiCert KeyLocker section of DigiCert ONE, we have made significant style updates to the platform to improve the user experience, including:

  • Visual design updates:

    • Updated color palette

    • Refined typography styles for better readability and consistency

  • Component redesigns:

    • Redesigned date range picker and date picker

    • Refreshed button component

    • Changed upload component

    • Redesigned left navigation

    • Updated error pages

We will continue making additional design and styles changes in future releases.

July 28, 2025

DigiCert® ONE version: 1.10498.13 | DigiCert KeyLocker: 1.1072.0

Included in this release:

Enhancements

Updated SMCTL sign command for simple signing

We have added two flags that allow users to sign without the need of third-party tools or libraries:

--simple

  • This flag signs without the need of third-party signing tools and libraries and applies to simplified signing workflows.

--unsigned

  • This flag signs unsigned files and applies to simplified signing workflows.

To learn more, see Sign binary commands.

July 9, 2025

DigiCert® ONE version: 1.10498.4 | DigiCert KeyLocker: 1.1042.0

Included in this release:

New

DigiCert® ONE services downtime during scheduled maintenance on July 12

DigiCert must perform maintenance affecting DigiCert® Software Trust Manager, DigiCert® Document Trust Manager, and the PrimoSign signing service in our DigiCert® ONE USA location during scheduled maintenance on July 12, 2025, 22:00 – 24:00 MDT (July 13, 04:00 – 06:00 UTC). For more details, refer to the DigiCert Global 2025 maintenance schedule.

During this time, the Software Trust Manager and Document Trust Manager will be down for approximately 10 minutes, and the PrimoSign signing service will be down for approximately 30 minutes.

Services will be restored as soon as we complete our maintenance.

How does this affect me?

  • The Software Trust Manager maintenance starts at 22:00 MDT (04:00 UTC). At this time, the Software Trust Manager will be down for 10 minutes.

  • The Document Trust Manager maintenance starts at 22:10 MDT (04:10 UTC). At this time, the Document Trust Manager will be down for 10 minutes.

  • The maintenance affecting Document Trust Manager’s PrimoSign signing service starts at 22:00 MDT (04:00 UTC). At this time, the PrimoSign signing service will be down for 30 minutes.

Affected services

  • DigiCert ONE in our USA location:

    • DigiCert Software Trust Manager

    • DigiCert Document Trust Manager

    • PrimoSign signing service

What can I do?

Plan accordingly:

  • Schedule any high-priority code signing and document signing certificate-related tasks and signings before or after the maintenance window.

  • Schedule high-priority PrimoSign document signings before or after the maintenance window.

  • Expect interruptions if you use the APIs for immediate certificate issuance and automated tasks.

  • Subscribe to the DigiCert Status page to get live maintenance updates. This subscription includes email alerts when maintenance begins and ends.

We apologize for any inconvenience. If you have questions or concerns, please contact your account manager or PKI Support | DigiCert.

June 18, 2025

DigiCert® ONE version: 1.10272.3 | DigiCert KeyLocker: 1.1042.0

Included in this release:

Enhancements

New flags for smctl sign commands

We have added new flags for SMCTL that allow users to define the application name in User Account Control (UAC) prompts.

This enhancement also enforces UTF-8 encoding to prevent character display issues, particularly on systems using Japanese language settings.

We have added the following flags:

2.

Flag

Description

--description

This flag:

  • Sets the description for the signed content.

  • Is only applicable when using Windows signtool.

  • Maps to the /d flag in signtool.

--desc-url

This flag:

  • Sets the URL for the description of the signed content.

  • Is only applicable when using Windows signtool.

  • Maps to the /du flag in signtool.


May 21, 2025

DigiCert® ONE version: 1.10046.5 | DigiCert KeyLocker: 1.1027.0

Included in this release:

Fixes

Resolved issue with smksp_cert_sync.exe execution failure

We resolved an issue where the smksp_cert_sync.exe process was failing during execution.

Resolved issue with PKCS#11 client tools functionality

We resolved an issue affecting PKCS#11 client tool commands, specifically the following commands: p11cat, p11ls, p11more, and p11od.

May 7, 2025

DigiCert® ONE version: 1.10046.1 | DigiCert KeyLocker: 1.1017.0

Included in this release:

Fixes

Issue with displaying “invalid date”

We resolved an issue where non-subscription KeyLocker orders were incorrectly displaying Invalid date in the Current subscription term field under Signature limit in DigiCert ONE.

This issue has been resolved; the field now only displays for retail subscription orders.

March 26, 2025

DigiCert® ONE version: 1.9525.6 | DigiCert KeyLocker: 1.964.0

Enhancements

KeyLocker renewal flows for subscriptions

We have introduced new renewal workflows for retail subscriptions in KeyLocker. With this release, when your subscription is renewed in CertCentral, KeyLocker will automatically update your order with the new subscription dates and allotted signatures.

Additionally with this release, email notifications are generated to KeyLocker account admins and assigned users regarding the new subscription period.

March 5, 2025

DigiCert® ONE version: 1.9525.1 | DigiCert KeyLocker: 1.954.0

Fixes

Fix for JCE code signing issue on Java 8

We have resolved an issue that prevented users from signing .jar files using the JCE method with Java 8.

Previously, attempts to sign using the documented jarsigner command failed, despite JCE method support for Java 8.

With this update, we have ensured compatibility of the JCE signing method with Java 8.

Notes::

  • For JDK versions 8 and 9, the Bouncy Castle library is required for the sign command.

  • For JDK version 10 and higher, the Bouncy Castle library is not required for the sign command.

February 13, 2025

DigiCert® ONE version: 1.9391.1 | DigiCert KeyLocker: 1.947.0

Enhancements

Upgraded client tools and software

To address user feedback, we have upgraded client tools and software. This update does not impact KeyLocker customers, and no user action is required.

Notifications for KeyLocker signature consumption

To keep users informed about KeyLocker signature consumption, in this release we have introduced email notifications.

When 80%, 90%, and 100% of signature units are used, an email will be sent to the assigned signer and all account admins, when applicable.

With this release:

  • Notifications trigger at 80%, 90%, and full consumption of signature units.

  • If the order is assigned to an admin, then all admins in the account will receive notifications.

  • If the order is assigned to a signer, then the signer and all admins will receive notifications.

  • Notifications will trigger when additional signature units are purchased and reach the 80% and 90% thresholds.

January 22, 2025

DigiCert® ONE version: 1.9100.6 | DigiCert KeyLocker: 1.933.0

Enhancements

Upgraded client tools and software

To address user feedback, we have upgraded client tools and software. This update does not impact KeyLocker customers, and no user action is required.

January 13, 2025

DigiCert® ONE version: 1.9100.2 | DigiCert KeyLocker: 1.926.0

Enhancements

Upgraded client tools and software

To address user feedback, we have upgraded client tools and software. This update does not impact KeyLocker customers, and no user action is required.

Fixes

December 17, 2024

DigiCert® ONE version: 1.8893.10 | KeyLocker: 1.904.0

Enhancement

Extended synchronization window for Cert Central certificate orders

In this release, we have increased the synchronization window from 7 days to 14 days for Cert Central certificate orders.

This update reduces synchronization failures and better aligns with business timelines.

October 3, 2024

DigiCert® ONE version: 1.8480.1 | DigiCert KeyLocker: 1.862.0

Enhancements

Upgraded client tools and software

To address reported vulnerabilities, we have upgraded certain client tools and software.

Fixes

Fixed login issues

We resolved an issue where clicking the KeyLocker icon to access a KeyLocker account would result in an error.

This issue has been resolved, ensuring the correct workflow to access your KeyLocker account.

September 18, 2024

DigiCert® ONE version: 1.8279.3 | DigiCert KeyLocker: 1.848.0

Enhancements

Version number change for KeyLocker client tools

You may have been notified about version 1.153.0 of KeyLocker tools; however, if you have already downloaded version 1.46.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.

August 21, 2024

DigiCert® ONE version: 1.9084.5 | DigiCert KeyLocker: 1.834.0

Enhancements

Version number change for KeyLocker client tools

You may have been notified about version 1.52.00 of KeyLocker tools; however, if you have already downloaded version 1.46.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.

July 31, 2024

DigiCert® ONE version: 1.7827.6 | DigiCert KeyLocker: 1.815.0

Enhancements

Version number change for KeyLocker client tools

You may have been notified about version 1.51.00 of KeyLocker tools; however, if you have already downloaded version 1.46.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.

July 18, 2024

DigiCert® ONE version: 1.7827.3 | DigiCert KeyLocker: 1.805.0

Enhancements

Version number change for KeyLocker client tools

You may have been notified about version 1.50.0 of KeyLocker tools; however, if you have already downloaded version 1.46.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.

July 3, 2024

DigiCert® ONE version: 1.7827.1 | DigiCert KeyLocker: 1.794.0

Enhancements

Version number change for KeyLocker client tools

You may have been notified about version 1.49.0 of KeyLocker tools; however, if you have already downloaded version 1.46.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.

June 19, 2024

DigiCert® ONE version: 1.7645.2 | DigiCert KeyLocker: 1.782.0

Enhancements

Account end date sync

KeyLocker accounts' end dates now automatically reflect the expiry date of the longest-valid certificate within the account. Users can align the account expiry date manually using the Sync certificate feature or wait for the automated sync job, which runs every Sunday at 2 AM, to ensure account end dates are accurately updated to match the latest certificate expiry.

May 22, 2024

DigiCert® ONE version: 1.7460.3 | DigiCert KeyLocker: 1.775.0

Enhancements

Version number change for KeyLocker client tools

You may have been notified about an updated version of KeyLocker tools; however, if you have already downloaded version 1.46.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.

May 15, 2024

DigiCert® ONE version: 1.7460.2 | DigiCert KeyLocker: 1.771.0

Fixes

SMCTL and PKCS11 library added to version 1.46.0 of Mac Clients

We identified that the SMCTL and PKCS11 library was unintentionally excluded in version 1.46.0 of the Mac Clients. We have rectified this issue without altering the version number. If you've already installed this version, download it again to ensure you have access to all required client tools.

May 8, 2024

DigiCert® ONE version: 1.7460.1 | DigiCert KeyLocker: 1.770.0

New

Java Cryptography Extension (JCE) library

We added a JCE library to our Client tool repository. JCE is part of the Java Development Kit (JDK) that facilitates digital signing of Java Archive (JAR) files and related artifacts. Using JCE for signing is preferred over PKCS11 and KSP library options due to its compatibility with various operating systems (Windows, Linux, macOS, Solaris, and AIX) and Java architectures, including 64-bit, 32-bit, and ARM processors.

Enhancements

Version number change for KeyLocker client tools

You may have been notified about an updated version of KeyLocker tools; however, if you have already downloaded version 1.41.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.

April 3, 2024

DigiCert® ONE version: 1.7277.0 | DigiCert KeyLocker: 1.765.0

Fixes

Users assigned to certificates

We have resolved an issue where the Certificate details page became skewed when multiple users were assigned as the certificate signer. This update ensures that the names are displayed clearly, without compromising user experience.

Signature limit for certificates purchased before November 3, 2024

We have removed references to signature limits for certificates purchased before November 3, 2024. This update aligns with our commitment to honor the service agreement at the time of purchase.

Keypair alias not displayed after syncing certificate

The sync certificate feature retrieves the latest certificate status from CertCentral. This action is used if your order status in CertCentral is different to your status in DigiCert® KeyLocker. While this works correctly, we noticed that after syncing the certificate, the keypair alias was not immediately displayed in the certificate details page. We have corrected this and all relevant information should display as expected.

Keypair alias filter

We have fixed an issue on the Certificates tab where filtering by keypair alias did not apply correctly, resulting in multiple certificates being listed. Now, when filtering by keypair alias, only the certificate associated with the specified keypair alias will be displayed in the list, ensuring accurate and streamlined results for users.

March 20, 2024

DigiCert® ONE version: 1.7083.4 | DigiCert KeyLocker: 1.756.0

Fixes

Healthcheck error updated

When a user ran the smctl healthcheck command and no signing tools were found in their system, the log files listed the following error message: "Error Tools cannot be null." We updated the error message to: "Unable to detect compatible signing tools." to improve the clarity that the user needs to install third-party signing tools.

March 19, 2024

DigiCert® ONE version: 1.7083.3 | DigiCert KeyLocker: 1.753.0

Enhancements

Signature and user limits for certificates purchased after November 3, 2024

KeyLocker implemented technical controls to enforce signature and signer limits on KeyLocker certificates purchased as stated in DigiCert's service terms on or after November 3, 2023. You can designate a user as the signer for the certificate in the Certificates tab in DigiCert​​®​​ KeyLocker. To increase the signature limit of your certificate, you can purchase additional signatures in increments of 1,000 from CertCentral. Learn more

March 13, 2024

DigiCert® ONE version: 1.7083.2 | DigiCert KeyLocker: 1.751.0

Fixes

Improved scalability and reliability

As an ongoing effort, we have improved the scalability and reliability of DigiCert​​®​​ KeyLocker. These updates ensures seamless operations even during peak usage and provides our users with a more efficient and robust user experience.

February 14, 2024

DigiCert® ONE version: 1.6887.2 | DigiCert KeyLocker: 1.731.0

New

SHA-384 signature algorithm ICAs

CertCentral now issues certificates off SHA-384 signature algorithm ICAs. While previously limited to SHA-256, this update enables users to utilize SHA-384 signatures based on their CA and ICA settings within CertCentral. Users can seamlessly leverage this feature to further strengthen their certificate management workflows.

February 8, 2024

DigiCert® ONE version: 1.6887.1 | DigiCert KeyLocker: 1.724.0

Fixes

Client tool download via API and plugins

We identified an issue preventing the download of DigiCert​​®​​ KeyLocker client tools via the no authentication API endpoint: /signingmanager/api-ui/v1/releases/noauth/{releaseName}/download and CI/CD plugins. We have fixed this issue, and users should be able to successfully download our client tools using the endpoint referred to above and DigiCert​​®​​ KeyLocker plugins.

February 7, 2024

DigiCert® ONE version: 1.6887.0 | DigiCert KeyLocker: 1.723.0

Enhancements

Version number change for KeyLocker client tools

You may have been notified about an updated version of KeyLocker tools; however, if you have already downloaded version 1.41.0 of the KeyLocker client tools, there is no need to update your client tools to the latest version as the changes made do not affect KeyLocker users.