Industry moved to RSA 3072-bit key minimum for code signing certificates
To comply with industry changes, DigiCert made the following changes to our code signing certificate process:
eToken and HSM changes
DigiCert supports two eTokens:
*Note: All existing 2048-bit key code signing certificates issued before June 1, 2021, will remain active. You can continue to use these certificates to sign code until they expire.
If you are reissuing your EV Code Signing certificate for an HSM device, you must submit a certificate signing request (CSR) with your request. To remain secure, certificates must use an RSA 3072-bit or ECC P-256-bit key size or larger. Refer to your HSM provider's documentation to create the CSR for your request.
Only HSM devices require you to submit a CSR with your request. The EV CS secure token reissue form doesn't include an option for submitting a CSR.
To remain secure, certificates must use at least a 2048-bit key size. Refer to your HSM provider's documentation to create the CSR for your request.
In your CertCentral account, in the left main menu, go to Certificate > Orders.
On the Orders page, in the Order # column, click the Quick View link for the EV Code Signing certificate you want to reissue.
In the Order # details pane (on the right), click Reissue Certificate.
HSM devices only – If you are using a secure token, skip to step 5.
On the Reissue Certificate for Order page, upload or paste your CSR into the Add Your CSR box.
Only HSM devices require you to submit a CSR with your request. This option does not appear on the form if you are using a secure token.
Unless you have a specific reason for choosing a different signature hash, DigiCert recommends using the default signature hash: SHA-256.
Select the platform you want to use your reissued certificate with.
Reason for Reissue
Specify the reason for the certificate reissue.
Click Request Reissue.
An approval for your EV CS certificate reissue may be required. If an approval is required, the EV CS verified contact for the organization is sent an email informing them that they need to approve the certificate reissue request. Once we receive their approval, we'll reissue your EV Code Signing certificate.
After we reissue your EV Code Signing certificate, you'll need to install it. See Installing your DigiCert® EV Code Signing Certificate onto a Secure Token instructions.
Then, you can start signing code. See EV Authenticode® Program Signing & Timestamping Using SignTool instructions.