You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Signtool使用YubiKey HSM密钥令牌及代码签名证书签名EXE?

Solution: Specify Target Certificate for YubiKey-Based Code Signing

When you run signtool sign /fd SHA256 "Installer.exe" without additional parameters, signtool automatically picks the first valid code signing certificate it finds in your local store. To force it to use your YubiKey-backed certificate, you need to explicitly reference the certificate using either its thumbprint or subject name.

Step 1: Get Your Target Certificate's Thumbprint

  • Open certmgr.msc (press Win+R, type certmgr.msc and hit Enter)
  • Navigate to Personal > Certificates
  • Locate your purchased code signing certificate (check the CN field to distinguish it from the SecurityDepartment certificate)
  • Right-click the certificate > Properties > Details tab
  • Scroll to find the Thumbprint field, copy its value (remove any spaces from the string)

Step 2: Sign with the Target Certificate Using Thumbprint

Use the /sha1 parameter followed by your certificate's space-free thumbprint to specify exactly which certificate to use:

signtool sign /fd SHA256 /sha1 <YOUR_CERT_THUMBPRINT> "Installer.exe"

Replace <YOUR_CERT_THUMBPRINT> with the thumbprint you copied earlier.

Step 3: Alternative - Use Subject Name to Specify Certificate

If you prefer using the certificate's subject name (CN), use the /n parameter with the exact CN of your purchased certificate:

signtool sign /fd SHA256 /n "Your Target Certificate CN" "Installer.exe"

Ensure the CN matches exactly (case-sensitive) what’s listed on your certificate.

Optional: Specify YubiKey's Cryptographic Service Provider (CSP)

If signtool still doesn’t recognize the YubiKey’s private key, explicitly define the YubiKey CSP. Most modern YubiKeys use this provider:

signtool sign /fd SHA256 /sha1 <YOUR_CERT_THUMBPRINT> /csp "YubiKey Smart Card Key Storage Provider" "Installer.exe"

For older YubiKey setups, try the legacy CSP:

signtool sign /fd SHA256 /sha1 <YOUR_CERT_THUMBPRINT> /csp "Microsoft Base Smart Card Crypto Provider" "Installer.exe"

Verify the Signature

After signing, confirm the correct certificate was used with:

signtool verify /pa "Installer.exe"

Check the output to ensure the CN matches your purchased certificate.

内容的提问来源于stack exchange,提问作者ankur kapoor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 02:55:12