# Code Signing certificates

**URL:** <https://forum.juce.com/t/code-signing-certificates/60849>\
**Category:** General JUCE discussion\
**Created:** [April 11, 2024, 7:17pm UTC](https://forum.juce.com/t/code-signing-certificates/60849 "2024-04-11T19:17:15Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![railjonrogut](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/railjonrogut/32/505_2.png) [@railjonrogut](https://forum.juce.com/u/railjonrogut)\
**Post date:** [April 11, 2024, 7:17pm UTC](https://forum.juce.com/t/code-signing-certificates/60849/1 "2024-04-11T19:17:16Z")

</div>

Currently use Comodo (which is set to expire in about 60 days) and have used Sectigo… but since the prices have pretty much doubled since the last time we purchased our certificates I found FastSSL who are also brokers for Sectigo and Comodo… and they offer their own code singing certificates at a substantially lower cost.

Has anyone here used them?

> **[FastSSL Code Signing Certificate - Cheap Code Signing @ $129/yr](https://cheapsslsecurity.com/fastssl/code-signing-certificate.html)**
>
> Get the cheapest price for a globally-trusted code signing certificate: the FastSSL Code Signing Certificate is fully trusted by Microsoft Windows.

Any issues using them with Windows && PACE?

Cheers,

Rail

---

<div class="post-metadata">

**Author:** ![saji8k](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@saji8k](https://forum.juce.com/u/saji8k)\
**Post date:** [April 12, 2024, 2:01am UTC](https://forum.juce.com/t/code-signing-certificates/60849/2 "2024-04-12T02:01:52Z")

</div>

You should hold off at least until [Build 2024](https://build.microsoft.com/en-US/home?utm_campaign=%5BR%5D%20Codestories%20Newsletter&utm_source=hs_email&utm_medium=email) if you can.

There may soon be a much easier and maybe a little cheaper system put in place to do code signing:

> [@Azure Code Signing for plugin developers (guide)](https://forum.juce.com/t/azure-code-signing-for-plugin-developers-guide/60391/14):
>
> On the private preview call today, the Microsoft signing team said that it will be public preview in early April. Here’s the pricing:

---

<div class="post-metadata">

**Author:** ![railjonrogut](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/railjonrogut/32/505_2.png) [@railjonrogut](https://forum.juce.com/u/railjonrogut)\
**Post date:** [April 12, 2024, 5:10am UTC](https://forum.juce.com/t/code-signing-certificates/60849/3 "2024-04-12T05:10:30Z")

</div>

Thanks. I think a quota system will end up being much more expensive for the amount of work I do than a yearly renewal which has no quota and the released signed products are time stamped so don’t expire.

Rail

---

<div class="post-metadata">

**Author:** ![saji8k](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@saji8k](https://forum.juce.com/u/saji8k)\
**Post date:** [April 12, 2024, 5:37am UTC](https://forum.juce.com/t/code-signing-certificates/60849/4 "2024-04-12T05:37:22Z")

</div>

Yes if you need to sign more than 5000 binaries a month, a code sign cert will probably be cheaper.

> released signed products are time stamped so don’t expire

Are you saying any released binaries signed by Azure Code Signing will eventually expire? Do you know how long they last? It certainly would be annoying to have to resign the same binary over and over again.

The only thing related to time I saw in the other thread’s document was this:

> Unlike certificates issued from authorities such as Sectigo, DigiCert and others, the certificates issued by ACS are only valid for a short time (e.g. several days) so that certificates cannot be stolen easily.

---

<div class="post-metadata">

**Author:** ![jdv](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/jdv/32/16401_2.png) [@jdv](https://forum.juce.com/u/jdv)\
**Post date:** [April 12, 2024, 7:43pm UTC](https://forum.juce.com/t/code-signing-certificates/60849/5 "2024-04-12T19:43:24Z")

</div>

We used [signmycode.com](http://signmycode.com) to get a Sectigo EV certificate on a physical dongle last year. I was skeptical about it, wondering how they can provide the same product so much cheaper. The only explanation I could find is that they are able to take advantage of volume discounts somehow. Anyway, after placing the order with [signmycode.com](http://signmycode.com) and submitting all the relevant information, I got a confirmation email from Sectigo and received the physical dongle.

I guess the process with the site you found would be similar.

---

<div class="post-metadata">

**Author:** ![railjonrogut](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/railjonrogut/32/505_2.png) [@railjonrogut](https://forum.juce.com/u/railjonrogut)\
**Post date:** [April 12, 2024, 8:07pm UTC](https://forum.juce.com/t/code-signing-certificates/60849/6 "2024-04-12T20:07:10Z")

</div>

Yes, they’re brokers who can discount the licenses… I was really wondering about the cheaper FastSSL “generic” certificate which is much cheaper at $129/year… but I don’t know anyone who’s actually tried it.

Cheers,

Rail

---

<div class="post-metadata">

**Author:** ![Fandusss](https://avatars.discourse-cdn.com/v4/letter/f/a4c791/32.png) [@Fandusss](https://forum.juce.com/u/Fandusss)\
**Post date:** [April 15, 2024, 9:27am UTC](https://forum.juce.com/t/code-signing-certificates/60849/9 "2024-04-15T09:27:22Z")

</div>

I’ve used Ksoftware without issue. Just another reseller.

---

<div class="post-metadata">

**Author:** ![alphamann](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/alphamann/32/18608_2.png) [@alphamann](https://forum.juce.com/u/alphamann)\
**Post date:** [May 27, 2024, 8:56am UTC](https://forum.juce.com/t/code-signing-certificates/60849/11 "2024-05-27T08:56:50Z")

</div>

I have been using an ev code signing certificate from signmycode because their price structure matches my budget after all I decided to purchase for 3 year

---

<div class="post-metadata">

**Author:** ![ibisum](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/ibisum/32/21288_2.png) [@ibisum](https://forum.juce.com/u/ibisum)\
**Post date:** [May 27, 2024, 9:21am UTC](https://forum.juce.com/t/code-signing-certificates/60849/12 "2024-05-27T09:21:19Z")

</div>

I can’t wait for you to make this child-proof, @sudara. 😉

---

<div class="post-metadata">

**Author:** ![TrustedSteed](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/trustedsteed/32/13862_2.png) [@TrustedSteed](https://forum.juce.com/u/TrustedSteed)\
**Post date:** [May 27, 2024, 11:44am UTC](https://forum.juce.com/t/code-signing-certificates/60849/13 "2024-05-27T11:44:01Z")

</div>

I just got an email from Sectigo last week saying that they are going to increase their prices on 1st June, and urging me to buy another certificate before their prices go up. My current EV has 6 months left.  
Perhaps they are concerned about Azure?  
I’d like to look into Azure, if its cheaper, I only have three products to EV sign. Has Build24 happened and Azure signing released? I don’t know much about Azure signing procedure at this stage.

> [@saji8k](#):
>
> You should hold off at least until [Build 2024](https://build.microsoft.com/en-US/home?utm_campaign=%5BR%5D%20Codestories%20Newsletter&utm_source=hs_email&utm_medium=email) if you can.
> 
> There may soon be a much easier and maybe a little cheaper system put in place to do code signing:

---

<div class="post-metadata">

**Author:** ![sudara](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/sudara/32/8071_2.png) [@sudara](https://forum.juce.com/u/sudara)\
**Post date:** [May 27, 2024, 11:52am UTC](https://forum.juce.com/t/code-signing-certificates/60849/14 "2024-05-27T11:52:03Z")

</div>

> [@TrustedSteed](#):
>
> Azure signing released? I don’t know much about Azure signing procedure at this stage.

Yes, see my [article](https://melatonin.dev/blog/code-signing-on-windows-with-azure-trusted-signing/) and [the active thread](https://forum.juce.com/t/azure-code-signing-for-plugin-developers-guide/60391).

---

<div class="post-metadata">

**Author:** ![daniel](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/daniel/32/790_2.png) [@daniel](https://forum.juce.com/u/daniel)\
**Post date:** [July 17, 2024, 7:39am UTC](https://forum.juce.com/t/code-signing-certificates/60849/18 "2024-07-17T07:39:36Z")

</div>

Just for fun I clicked on all people posting they use signmycode, and they all posted pretty much one message and disappeared…  
Sounds bot-ty to me 🤔

EDIT: thanks mods for cleaning that up 🙂
