AWS Security Blog

Tag: SignTool

Figure 1: Architectural overview

Signing executables with HSM-backed certificates using multiple Windows instances

December 22, 2025: CloudHSM SDK3 is no longer supported. AWS recommends that you use the latest version, AWS CloudHSM KSP SDK5. We updated this post with SDK5 functionality and features. Customers use code signing certificates to digitally sign software, documents, and other certificates. Signing is a cryptographic tool that lets users verify that the code […]

Signing executables with Microsoft SignTool.exe using AWS CloudHSM-backed certificates

Code signing is the process of digitally signing executables and scripts to confirm the software author and to demonstrate that the code has not been altered or corrupted since it was signed. Packaged software uses branding and trusted sales outlets to assure users of its integrity, but these guarantees are not available when code is […]