IV Code Signing
IV Code Signing
Key Benefits
Your name on every installer
Your verified personal name is displayed when users run your software: not “Unknown Publisher”.
Tamper-evident signing
Any modification after signing, even a single bit flipped, cryptographically invalidates the signature. Windows, macOS, and inspection tools detect the break immediately and alert users to tampering.Cloud signing compatible
Works with SSL.com eSigner for Code to sign binaries directly from CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps) without distributing hardware tokens to build machines.Trusted on all Windows versions
IV certificates are trusted for Microsoft Authenticode executable signing across Windows 11, Windows 10, Windows Server 2025, Server 2022, Server 2019, and every earlier supported Windows release.Who Is It For?
Independent developers
Independent developers shipping tools, utilities, command-line apps, and personal projects under a verified individual name: the IV tier gives solo developers access to Authenticode signing without a business entity.Open source maintainers
Open source maintainers who want verifiable, signed release artifacts for their community. Downstream packagers and distributors verify each release against the maintainer’s published public key.Freelance developers
Freelance developers distributing software to clients with a verified personal name on every installer: reinforces contractor identity and protects clients from tampered releases.Students & hobbyists
Students, researchers, and hobbyists distributing publicly available software with professional-grade Authenticode signing. IV is the lowest-cost path to Windows-trusted signed binaries.Purchase & Pricing
1. Select Certificate Duration
2. Select Key Storage & Delivery (optional)
eSigner Cloud Signing
Sign anywhere using eSigner.com. No hardware required.eSigner Cloud Signing
Sign anywhere using eSigner.com. No hardware required.Select the monthly or annual signature volume tier. Any unused signatures will roll over into the next month or year if there is an active certificate. Each tier provides a certain number of included credentials which are pre-selected based on the selected tier. Extra credentials can be purchased at $20 per month. New certificates will receive 30-days free of eSigner cloud signing. After the first 30 days, your monthly or annual subscription fees will be applied.
YubiKey
Physical TokenStandard
3ā5 business days after validation (Continental US)Express + $329.00
1 day after validationBring Your own Cloud HSM
Self-managed infrastructureSSL.com must attest your key to your chosen provider before issuing the certificate. This fee is a one-time charge per order.
Looking for a simpler option? SSL.com eSigner for Code provides cloud-based signing with no HSM to provision, no attestation fee, and a lower total cost for most teams.
Bring your own on-premises HSM
SSL performs an attestation ceremony for your compliant on-premises HSM.Please contact sales.
3. Validation Speed (optional)
Choose how quickly your organization or identity is validated before your certificate is issued.
Standard
3ā5 day validation Ā· 2ā3 day US shipping Validation completed after all agreements, entity info submitted, and a successful callback to a listed phone number. IncludedExpedited
2 business day validation Ā· overnight US delivery 2 business days priority validation from first complete submission and callback. Token shipped overnight in continental US. +$599.00Order Summary
How It Works
1: Purchase
Select IV duration and complete your order.
2: Identity validation
SSL.com validates your personal identity: government-issued ID required.
3: Certificate issued
Certificate delivered to your account. Install on a FIPS hardware token or enroll in eSigner for Code.
4: Sign your code
Sign executables, scripts, and installers. Users see your verified personal name on the installer screen.
5: Timestamp
Always timestamp at signing: extends signature validity beyond certificate expiry.
Compliance & Standards
CA/B Forum Code Signing BR
Microsoft Authenticode
WebTrust for Code Signing BR
2048+ bit RSA & ECC
Frequently Asked Questions
Not necessarily. IV private keys can be stored in software (PKCS#12 file) or on a FIPS hardware token. To use eSigner for Code cloud signing, enrollment is required after issuance.
IV certificates cover Windows Authenticode signing. macOS app signing requires Apple Developer ID certificates issued through Apple’s own developer program.
IV certificates are typically issued within minutes of identity validation. SSL.com validates your personal identity using government-issued ID.
Yes: always timestamp at signing time. A valid timestamp means your signed code remains trusted indefinitely, even after the certificate itself expires.