cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
DaveSimmons
Level 4

Amazon CloudHSM for code signing?

Jump to solution

DigiCert is ending support for file-based code signing certificates later this year:

"Starting on November 15, 2022, at 00:00 UTC, industry standards will require private keys for OV code signing certificates to be stored on hardware certified as FIPS 140 Level 2, Common Criteria EAL 4+, or equivalent."

We need to sign InstallShield Premiere setups at multiple locations, and also sign using AWS cloud servers, so using a USB device for signing isn't going to work for us.

Does InstallShield support using a cloud HSM now? (Search didn't find anything) 

If not, is there a roadmap for adding cloud HSM support? 

Labels (1)
(1) Solution
Revenera_Ian
Revenera Moderator Revenera Moderator
Revenera Moderator

Hi @DaveSimmons,

Thank you for your post.

If you're referring to AWS CloudHSM digital signing, yes, InstallShield supports this.

Please read the documentation at the bottom of the page at the following link for more information:

https://docs.revenera.com/installshield27helplib/helplibrary/SupportforAWSHSMBasedDigitalSigning.htm?Highlight=CloudHSM#introduction_1989478993_1169972

Please give these steps a try. Do they work for you?

Please let us know if you have any questions or concerns. Thanks!

View solution in original post

0 Kudos
(2) Replies
Revenera_Ian
Revenera Moderator Revenera Moderator
Revenera Moderator

Hi @DaveSimmons,

Thank you for your post.

If you're referring to AWS CloudHSM digital signing, yes, InstallShield supports this.

Please read the documentation at the bottom of the page at the following link for more information:

https://docs.revenera.com/installshield27helplib/helplibrary/SupportforAWSHSMBasedDigitalSigning.htm?Highlight=CloudHSM#introduction_1989478993_1169972

Please give these steps a try. Do they work for you?

Please let us know if you have any questions or concerns. Thanks!

0 Kudos

@Revenera_Ian This documentation just states just switch that value to x64 but how else do you get it to work? I see no option for AWS CloudHSM in the certificate interface in Installshield.  Also is there support for Azure KeyVault HSMs? 

0 Kudos