Reissue an EV Code Signing certificate

Learn how to reissue your Extended Validation (EV) Code Signing certificate

Industry moved to RSA 3072-bit key minimum for code signing certificates

To comply with industry changes, DigiCert made the following changes to our code signing certificate process:

  • Only issues RSA 3072-bit key or larger code signing certificates*
  • Uses new intermediate CA and root certificates to issue our code signing and EV code signing certificates: RSA and ECC

eToken and HSM changes

DigiCert supports two eTokens:

  • 5110 CC for RSA 4096-bit and ECC P-256-bit key certificates
  • 5110 FIPS for ECC P-256 and P-384-bit key certificates

HSM must:

  • Support RSA 3072-bit or ECC P-256-bit keys sizes or larger
  • Be FIPS 140-2 Level 2+ or Common Criteria EAL4+ compliant devices

*Note: All existing 2048-bit key code signing certificates issued before June 1, 2021, will remain active. You can continue to use these certificates to sign code until they expire.

Learn more about the change to 3072-bit key code signing certificates.

Before you begin

If you are reissuing your EV Code Signing certificate for an HSM device, you must submit a certificate signing request (CSR) with your request. To remain secure, certificates must use an RSA 3072-bit or ECC P-256-bit key size or larger. Refer to your HSM provider's documentation to create the CSR for your request.

Only HSM devices require you to submit a CSR with your request. The EV CS secure token reissue form doesn't include an option for submitting a CSR.

To remain secure, certificates must use at least a 2048-bit key size. Refer to your HSM provider's documentation to create the CSR for your request.

Reissue your EV CS certificate

  1. In your CertCentral account, in the left main menu, go to Certificate > Orders.

  1. On the Orders page, in the Order # column, click the Quick View link for the EV Code Signing certificate you want to reissue.

  1. In the Order # details pane (on the right), click Reissue Certificate.

  1. HSM devices only – If you are using a secure token, skip to step 5.

    On the Reissue Certificate for Order page, upload or paste your CSR into the Add Your CSR box.

Only HSM devices require you to submit a CSR with your request. This option does not appear on the form if you are using a secure token.

  1. Signature Hash

    Unless you have a specific reason for choosing a different signature hash, DigiCert recommends using the default signature hash: SHA-256.

  1. Server Platform

    Select the platform you want to use your reissued certificate with.

  1. Reason for Reissue

    Specify the reason for the certificate reissue.

  1. Click Request Reissue.

What's next

An approval for your EV CS certificate reissue may be required. If an approval is required, the EV CS verified contact for the organization is sent an email informing them that they need to approve the certificate reissue request. Once we receive their approval, we'll reissue your EV Code Signing certificate.

After we reissue your EV Code Signing certificate, you'll need to install it. See Installing your DigiCert® EV Code Signing Certificate onto a Secure Token instructions.

Then, you can start signing code. See EV Authenticode® Program Signing & Timestamping Using SignTool instructions.