Establishing trust and integrity with code signing

Secure code signing is essential to ensure the authenticity and integrity of executable program files, especially updates delivered via unsecured channels like the Internet. This whitepaper explores:

  • The technology underlying secure code signing, including the critical role played by hardware security modules
  • The steps developers can take to build a high assurance code signing process
  • Real world examples of code signing failures, such as Duqu, Stuxnet and others, where organizations ignored best practices

