📄️ Can a remote code signing certificate be used for both UKey and cloud?
The private key of a remote code signing certificate is generated in a cloud HSM and cannot be exported, so the same certificate cannot be used for both remote signing and storage on a physical UKey. Certificates from Sectigo, DigiCert and GlobalSign brands are currently supported.
📄️ How Does the Remote Code Signing Service Ensure Security?
sslTrus remote code signing service stores private keys in FIPS 140-3 certified hardware cryptographic modules with never exportable private keys, provides complete audit logs, and encrypts data during the entire transmission process to ensure a secure and reliable signing process.
📄️ How are remote code signature counts calculated?
sslTrus remote code signing service counts 1 signature for each successful API call that completes a signature, regardless of file size. Failed signatures or invalid requests are not billed, and billing rules are transparent and reasonable.
📄️ How to handle the expiration of remote code signing service?
You can renew your remote code signing service before expiration to continue using the original certificate. If you run out of signature quota, you can purchase an add-on package, which shares the same validity period as the main plan. This article also explains the relationship between certificate expiration and service expiration.
📄️ Does the Remote Code Signing Service Support Multi-Year Purchases?
sslTrus remote code signing service currently only supports 1-year subscriptions, and the associated certificate also has a 1-year validity period. Once the service is activated, unsubscription is not supported. Please confirm your requirements before purchasing.
📄️ How many signatures are counted for multiple files in one program?
Remote code signing is billed based on the number of files: one file counts as one signature (for example, a program with 100 files will deduct 100 signature counts). Failed signatures or invalid requests caused by parameter errors will not be counted. Learn more about the detailed billing rules.
📄️ Pre-signing Certificate Validation and Signature Override Rules
Detailed explanation of the usage of --verify and --nest parameters in the cloud sign command: --verify is used to validate the certificate trust status before signing, and aborts the signing process if the certificate is not trusted; --nest controls the signature override behavior, and the default false value will overwrite the original signature. Learn the parameter usage to avoid signing errors.
📄️ Does Cloud Sign provide timestamp service?
Cloud Sign service does not provide timestamp servers; you need to use the official timestamp addresses of major CAs (such as Sectigo, DigiCert, etc.). Timestamps ensure that historical signatures remain valid after the certificate expires. It is recommended to use stable CA addresses (such as http://timestamp.sectigo.com).
📄️ What device is the cloud signing private key stored on?
The private key for the cloud signing service is stored in a Thales Luna K7 Hardware Security Module (HSM), which meets the FIPS 140-3 security standard, exceeding the mandatory requirement for EV certificates set by the CA/B Forum (FIPS 140-2 Level 2/3), to ensure the highest level of security protection for certificate private keys.
📄️ Does document signing support remote signing?
Does document signing support remote signing?