Skip to main content
This section runs the following Microsoft SignTool commands: signtool sign and signtool verify.
The signtool sign command is relevant to this integration because it is the only SignTool command that initiates communication with the CryptoHub. SignTool must be able to access the private key stored in CryptoHub to complete the code signing operation successfully.

Sign a file

The following example signs an .exe file, but you can sign other types of files by using SignTool. See the following document for details:https://docs.microsoft.com/en-us/windows/win32/seccrypto/cryptography-tools
Perform the following steps to sign a file using the configured code Signing certificate:
1
Open PowerShell or Windows Command Prompt and run the following command, replacingMyCertificate with the Subject Name of your certificate and example.exe with the name of the file that you are signing:
PowerShell
If the command succeeds, you should receive the following message:
None

Verify the file

To verify the file that was signed, run the following command:
Text
If the command succeeds, you should see output similar to the following example:
None