Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 701221
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 14, 20262026-05-14T03:35:08+00:00 2026-05-14T03:35:08+00:00

I recently acquired a code signing certificate for my employer, but I am not

  • 0

I recently acquired a code signing certificate for my employer, but I am not the InstallShield developer who will sign the binaries before distribution. I know I can export the certificate along with its private key, but where do I store it so the InstallShield developer can install it on his machine? Should I remove it from my machine once I give it to the person doing the signing? Where do I store the master copy? Obviously, source control is not the best place, unless I lock down that directory in SVN.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-14T03:35:09+00:00Added an answer on May 14, 2026 at 3:35 am

    Enforce Security Policies for Private Keys

    Remember: a private key in conjunction with released signed binaries is your company’s identity. Policies for handling such keys can’t be strict enough.

    Enforce that YOU are the only persion in your company who will be capable (and responsible) of signing executables.

    If this is not an option then let all PKI-involved employees sign an explicit non-disclosure agreement with a high fine – a much higher sense of responsibility should be the result.

    Key Transfers

    • use portable media (like a dedicated USB stick or CD-ROM) – I’d prefer a read-only media
    • let the receipt be witnessed by another employee
    • let the recipient and the witness sign a form about the key-receipt

    Storage of the Master Copy

    Store the master copy redundant on at least 3 drives at different geographical locations where you have exclusive access to. Also think about encrypting the copies with strong encryption algorithms like AES-256 (in a 7z file for example).

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I am a C# Developer, and I recently acquired a project at work that
We have a client who has just recently acquired their first SharePoint 2010 system.
My employer was recently acquired by a much larger company. In the process of
I recently acquired Crap4j, and ran it but got the following error: No test
Having recently discovered design patterns, and having acquired the excellent Head First Design Patterns
Recently I started noticing a repetition in some of my code. Of course, once
I recently acquired a Metrologic Barcode scanner (USB port), as everyone already knows it
I have recently acquired a ViewSonic G Tablet running Android 2.2 for the development
Recently, we discovered odd behavior in some old code. This code has worked for
Recently I have been refactoring some of my C# code and I found a

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.