如何通过Signtool使用YubiKey HSM密钥令牌及代码签名证书签名EXE?
When you run signtool sign /fd SHA256 "Installer.exe" without additional parameters, signtool automatically picks the first valid code signing certificate it finds in your local store. To force it to use your YubiKey-backed certificate, you need to explicitly reference the certificate using either its thumbprint or subject name.
Step 1: Get Your Target Certificate's Thumbprint
- Open
certmgr.msc(press Win+R, typecertmgr.mscand hit Enter) - Navigate to Personal > Certificates
- Locate your purchased code signing certificate (check the CN field to distinguish it from the SecurityDepartment certificate)
- Right-click the certificate > Properties > Details tab
- Scroll to find the Thumbprint field, copy its value (remove any spaces from the string)
Step 2: Sign with the Target Certificate Using Thumbprint
Use the /sha1 parameter followed by your certificate's space-free thumbprint to specify exactly which certificate to use:
signtool sign /fd SHA256 /sha1 <YOUR_CERT_THUMBPRINT> "Installer.exe"
Replace <YOUR_CERT_THUMBPRINT> with the thumbprint you copied earlier.
Step 3: Alternative - Use Subject Name to Specify Certificate
If you prefer using the certificate's subject name (CN), use the /n parameter with the exact CN of your purchased certificate:
signtool sign /fd SHA256 /n "Your Target Certificate CN" "Installer.exe"
Ensure the CN matches exactly (case-sensitive) what’s listed on your certificate.
Optional: Specify YubiKey's Cryptographic Service Provider (CSP)
If signtool still doesn’t recognize the YubiKey’s private key, explicitly define the YubiKey CSP. Most modern YubiKeys use this provider:
signtool sign /fd SHA256 /sha1 <YOUR_CERT_THUMBPRINT> /csp "YubiKey Smart Card Key Storage Provider" "Installer.exe"
For older YubiKey setups, try the legacy CSP:
signtool sign /fd SHA256 /sha1 <YOUR_CERT_THUMBPRINT> /csp "Microsoft Base Smart Card Crypto Provider" "Installer.exe"
Verify the Signature
After signing, confirm the correct certificate was used with:
signtool verify /pa "Installer.exe"
Check the output to ensure the CN matches your purchased certificate.
内容的提问来源于stack exchange,提问作者ankur kapoor

