SSL certificates can be valid for at most 199 days. From 15 March 2027 the limit becomes 99 days. Read more →

Code Signing certificate with USB token

Every Code Signing certificate from FairSSL includes a USB crypto device at no extra cost. FIPS 140-2 Level 2 certified hardware. The private key is generated on the token and can never be exported or copied. Sign with signtool.exe, Jsign or macOS codesign/productsign.

GlobalSign ships its own token, usually arriving within about a week. For DigiCert, FairSSL ships a SafeNet eToken 5110 CC with PostNord for next-business-day delivery, usually received within 2 working days, because the parcel has to be sent before 10:00 to go out the next business day. The same FairSSL express shipping can be added for GlobalSign as a paid option.

What is a SafeNet USB token?

SafeNet eToken 5110 CC is a certified USB crypto device from Thales (formerly Gemalto). It stores your Code Signing private key in tamper-resistant hardware. The key is generated inside the token and cannot be exported. All signing operations happen on the token itself.

This meets the CA/Browser Forum requirement for FIPS 140-2 Level 2+ key storage that has been mandatory since June 2023.

How it works

1

Buy a Code Signing certificate from FairSSL

USB token delivery is the default.

2

Complete organisation validation

GlobalSign OV can be done the same working day during business hours, GlobalSign EV usually takes one working day more. DigiCert OV and EV usually take 2-3 working days. These times assume we can reach you and that you return the signed documents right away.

3

Receive USB token

GlobalSign ships its own token after validation, usually arriving within about a week. For DigiCert, FairSSL ships the token with PostNord once the postal address is confirmed, usually received within 2 working days. FairSSL express shipping can be added for GlobalSign as a paid option.

4

Install SafeNet drivers on your signing machine

SafeNet Authentication Client must be installed before retrieving the certificate.

5

Retrieve and install your certificate on the token

Using Fortify for GlobalSign, or direct download for DigiCert.

6

Sign your code

Using signtool.exe, Jsign or codesign.

Important security warnings

The USB token locks permanently if the wrong Administrator Password or PUK is entered 5 times. Contact us to purchase a new device if this happens.

SafeNet drivers must be installed before retrieving the certificate. On renewal: update to the latest driver version.

The certificate and private key cannot be copied or exported from the USB token.

Signing with USB token

Windows: signtool.exe

Included in the Windows SDK. Can also be used via AzureSignTool. Insert the token and enter your PIN when prompted.

Java: Jsign

Jsign is cross-platform and open source. Works with USB tokens via PKCS#11.

macOS: codesign and productsign

Apple's built-in signing tools. The SafeNet token registers automatically in macOS Keychain.

Timestamping

Always use RFC 3161 timestamping when signing. It ensures your signature remains valid after the certificate expires.

Common timestamp servers:

  • DigiCert: http://timestamp.digicert.com
  • GlobalSign: http://timestamp.globalsign.com/tsa/r6advanced1
  • Sectigo: http://timestamp.sectigo.com
signtool sign /fd sha256 /tr http://timestamp.digicert.com /td sha256 /a "MyApp.exe"

Extra USB tokens

Extra SafeNet tokens can be purchased from FairSSL. Contact us for a price. Useful if you need multiple signing stations. The certificate can only exist on one token (non-exportable), but having spare tokens is practical for replacement scenarios.

RDP limitation

USB tokens cannot be forwarded over standard Windows Remote Desktop (RDP). TeamViewer, AnyDesk and similar remote desktop tools do support USB token passthrough.

For automated or remote signing, consider Azure Key Vault or Google Cloud KMS instead. See our HSM key storage comparison.

GlobalSign USB token setup guide

Step-by-step guide for installing SafeNet drivers, retrieving your certificate via Fortify and your first signing.

Read the guide →

Code Signing certificates with USB token

OV Code Signing

DigiCert

DigiCert CodeSign OV

OV

DigiCert OV Code Signing. SafeNet USB token included, shipped by FairSSL.

from €475 €400 /year See details →
GlobalSign

GlobalSign CodeSign

OV

GlobalSign OV Code Signing. USB token from GlobalSign, usually arriving within about a week.

from €375 /year See details →

EV Code Signing

Frequently asked questions about Code Signing with USB token

Find answers to the most common questions about SSL certificates and FairSSL.

Yes. All Code Signing certificates from FairSSL include a hardware token at no extra cost. GlobalSign ships its own token, usually arriving within about a week. For DigiCert, FairSSL ships a SafeNet eToken 5110 CC with PostNord for next-business-day delivery, usually received within 2 working days, because the parcel has to be sent before 10:00 to go out the next business day. The same FairSSL express shipping can be added for GlobalSign as a paid option.
Yes. Install the SafeNet driver on the new machine and insert the token. The certificate travels with the token.
Yes, on renewal your new certificate can be installed on your existing token, provided it is a SafeNet eToken 5110 CC in working condition.
If the PUK code is available, it can be used to reset the PIN. If both PUK and Administrator Password are forgotten or blocked (5 incorrect attempts), the token is permanently locked and must be replaced.
It is technically possible to pass the PIN via command-line parameters to signtool, but the USB token must be physically inserted in a machine. For fully automated pipelines we recommend Azure Key Vault or Google Cloud KMS.

Ready to sign with USB token?

A code signing certificate requires your company to be validated, so it is not issued in minutes. We help you choose the certificate and key storage and keep you informed during validation.