Last updated 9 March 2023. GlobalSign and Sectigo set the final deadline for issuance without physical security to 23 April 2023.
The deadline for switching to physical key security has been moved from 15 November 2022 to no later than 1 June 2023.
Code Signing certificates are issued with two levels of validation: Organisation Validation "OV" and the higher-requirement Extended Validation "EV", which has the following differences compared to OV:
- Higher requirements for company validation.
- Increased trust boost in Microsoft's SmartScreen download filter.
- Requirement that the issuer ensures the certificate's private key is physically secured, e.g. with a USB crypto key or network HSM,
which must comply with the FIPS 140-2 Level 2 or Common Criteria EAL 4+ standard.
A detail many overlook with standard/OV Code Signing is that the key must still be secured, but it is the user's responsibility rather than the issuer's. This means you accept terms stating that you must protect the key against copying and theft.
Because most people ignore this detail, it is also common practice for OV Code Signing certificates to be copied and installed in multiple locations, typically without any key protection.
Microsoft therefore submitted a proposal to extend the EV key protection and physical security requirements to also apply to OV Code Signing. Their original proposal was submitted on 5 May 2022 and supported by DigiCert and Entrust. The proposal was adopted by vote and was to take effect no later than 15 November 2022. On 27 September, Microsoft submitted a proposal to move the start date to 1 June 2023, on the grounds that there should be at least one year's notice before it takes effect. The proposal was adopted.
There is now a deadline of 1 June 2023, before which it will no longer be possible to issue Code Signing OV certificates without physical key security.
This means, among other things:
- At renewal, most customers must first wait to receive a USB crypto dongle, e.g. a Thales SafeNet 5110 cc. This can cause unexpected delays in renewal.
- There is and may continue to be a shortage of USB crypto devices, making it difficult to even obtain a key to install on. Most devices today only support 2048-bit RSA keys and require a significant process to handle the astronomically larger keys (3072-bit RSA) now required for Code Signing.
- There are many who currently use Code Signing on multiple machines or in automated processes, e.g. in development pipelines that automatically sign code. It may become difficult or impossible to make these work with their current setup.
- It may become necessary to use online Code Signing solutions, network HSM, or cloud-based solutions such as Azure KeyVault (Premium) to perform the same processes as today.
- Code Signing OV certificates issued before 1 June 2023 will continue to work until expiry (e.g. 3 years), but cannot be reissued without physical security.
We recommend the following:
- If it is important to obtain the certificate without physical key security, e.g. because it is used in multiple locations, order a 3-year certificate no later than May 2023.
We can help if there is remaining time on an existing certificate. - Where possible, secure your keys regardless of whether it is required. For example, use a TPM chip.
- Consider using online solutions such as Azure KeyVault (Premium) or AWS KMS now.
- Renew early if you need a USB crypto device. It will be included in the price from 1 June 2023, which is likely to result in price changes.
Deadlines for issuance without a USB crypto device:
We have now received the following information on the last chance to issue or reissue existing certificates without physical security, from the various CAs.
GlobalSign no later than 23 April 2023 – No longer possible.
23 April 2023 is the last day it is possible to issue or reissue GlobalSign OV Code Signing certificates. If validation and issuance are not completed before 24 April 2023, issuance must take place on a physical USB crypto dongle or on a certified HSM. The price increases by
DigiCert no later than 15 May 2023.
DigiCert removes the option to choose without physical security on 16 May 2023. Certificates must be issued before 30 May 2023, after which they will no longer issue without physical security.
Sectigo no later than 29 May 2023.
Sectigo recommends ordering with a USB crypto device or HSM from 15 May 2023. Certificates that are not issued by 30 May 2023 will be revoked, and reissuance with physical security will be required. Additionally, the price of their OV Code Signing certificates increases.