# Current Options for Code Signing on Windows

**URL:** <https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812>\
**Category:** Windows\
**Created:** [April 14, 2025, 9:48am UTC](https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812 "2025-04-14T09:48:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Benoit1](https://avatars.discourse-cdn.com/v4/letter/b/73ab20/32.png) [@Benoit1](https://forum.juce.com/u/Benoit1)\
**Post date:** [April 14, 2025, 9:48am UTC](https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812/1 "2025-04-14T09:48:55Z")

</div>

Hey everyone,

I’m looking into code signing for my JUCE plugin on Windows, and the situation seems to be getting trickier. I’ve seen Azure Trusted Signing recommended a few times here on the forum, but it’s now only available in the US and Canada for new consumers ([https://techcommunity.microsoft.com/blog/microsoft-security-blog/trusted-signing-public-preview-update/4399713](https://techcommunity.microsoft.com/blog/microsoft-security-blog/trusted-signing-public-preview-update/4399713)).

From what I gather:

It’s getting harder to avoid SmartScreen warnings with just an OV certificate.

EV seems to offer instant trust, but it’s more expensive and involves extra steps or hardware.

There’s also the option of cloud-based signing vs using a local USB token/private key.

A few questions:

Should I go for an EV or OV certificate as a small indie dev?

Is there a significant difference between cloud-based signing and using a local/private key?

Are there any reputable certificate authorities people here recommend?

And finally — is there any practical difference between signing the .exe installer versus signing the .vst3 plugin directly ?

Would love to hear your thoughts or recent experiences.

Thanks!

---

<div class="post-metadata">

**Author:** ![asimilon](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/asimilon/32/4235_2.png) [@asimilon](https://forum.juce.com/u/asimilon)\
**Post date:** [April 14, 2025, 11:14am UTC](https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812/2 "2025-04-14T11:14:17Z")

</div>

> [@Benoit1](#):
>
> it’s now only available in the US and Canada

wow, what an awful step by Microsoft, I guess it was too much of a hassle dealing with the rest of the world, although the wording

> [@](#):
>
> Onboarding for individual developers and all other organizations will not be directly available for the remainder of the preview

does leave room for interpretation that once the preview period is finished they’ll open it up again.  
Fingers crossed! 🤞

> [@Benoit1](#):
>
> Should I go for an EV or OV certificate as a small indie dev?

This is difficult thing really, the price for OV certs has gone up significantly, to the degree that the difference to EV didn’t seem that bad when I was looking at it before I managed to get into the ATS preview program. OV certs will trigger the SmartScreen nonsense until you manage to build trust, and every time you renew the trust is reset iirc.

> [@Benoit1](#):
>
> Is there a significant difference between cloud-based signing and using a local/private key?

Price. The cloud based signing seemed excessively expensive and limitied.

> [@Benoit1](#):
>
> is there any practical difference between signing the .exe installer versus signing the .vst3 plugin directly ?

I’ve never signed the plugins themselves, but I did read that signing the plugins can help alleviate false positives for anti-virus. If you don’t sign the installer though you’ll get the yellow “untrusted” warning when the installer attempts to raise its admin rights.

---

<div class="post-metadata">

**Author:** ![Benoit1](https://avatars.discourse-cdn.com/v4/letter/b/73ab20/32.png) [@Benoit1](https://forum.juce.com/u/Benoit1)\
**Post date:** [April 14, 2025, 1:34pm UTC](https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812/3 "2025-04-14T13:34:21Z")

</div>

Thanks for the reply.

It sounds like Microsoft does plan to make Azure Trusted Signing available more widely (they talk about global availability) after the preview phase, but there’s no clear timeline yet.

Quick follow-up. Do you or anyone else have any certificate providers you’d recommend, or ones to avoid?

Thanks again.

---

<div class="post-metadata">

**Author:** ![PeterRoos](https://avatars.discourse-cdn.com/v4/letter/p/7ab992/32.png) [@PeterRoos](https://forum.juce.com/u/PeterRoos)\
**Post date:** [April 14, 2025, 3:22pm UTC](https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812/4 "2025-04-14T15:22:49Z")

</div>

I am in The Netherlands and I am paying monthly for this MS EV signing service.

A guick glance at the MS text: it seems to be about NEW customers for this service.

---

<div class="post-metadata">

**Author:** ![Benoit1](https://avatars.discourse-cdn.com/v4/letter/b/73ab20/32.png) [@Benoit1](https://forum.juce.com/u/Benoit1)\
**Post date:** [April 14, 2025, 3:51pm UTC](https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812/5 "2025-04-14T15:51:58Z")

</div>

Yes Peter, it’s about new customers only, that’s what the link in my first post was referring to. Sorry for not phrasing it more clearly.

---

<div class="post-metadata">

**Author:** ![TobbenTM](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.juce.com/tobbentm/32/18335_2.png) [@TobbenTM](https://forum.juce.com/u/TobbenTM)\
**Post date:** [April 14, 2025, 7:31pm UTC](https://forum.juce.com/t/current-options-for-code-signing-on-windows/65812/6 "2025-04-14T19:31:38Z")

</div>

You’ll also have issues with the Microsoft Azure solution as long as you don’t have 3 years of company history. I wrote up an article on using your own cloud key store as an alternative, using AWS KMS, but others have written about using Azure KeyVault etc: [Signing Windows binaries using AWS KMS](https://moonbase.sh/articles/signing-windows-binaries-using-aws-kms/)

This approach is a tad trickier than using hardware dongles, BUT you can sign stuff in CI pipelines which for us far outweigh the drawbacks. Once set up, it’s super easy to use too, and very cheap. Literally only have to pay for an EV cert (would always recommend EV certs, hard to avoid the SmartScreen warnings without).
