Configuring Signing Policy

  1. Go to Menu > Code Signing > GROUPS & POLICIES > Signing Policy.
    The Signing Policy page is displayed.
  2. From the top-right corner of the page, click Create.
  3. Enter/select the Policy details.
    Table 1. Field description for the Policy Details section
    Field name Description
    *Policy Name Provide a unique name for the signing policy. No special characters other than '.', '-','_' are allowed. The name should not start with special characters.
    *Hash Function Select the hash function you want to configure for code signing. Dropdown options: SHA-1, SHA-256, SHA-384, SHA-512.
    Timestamping Choose a trusted timestamping authority from the dropdown list. Dropdown options: DigiCert, Entrust, Global Sign, IdenTrust, Sectigo, Other, None. If you choose Other, provide the timestamping URL.
    Note: If you select None, the Timestamping will not be applied to the configured signing policy.
    *Signing Type Choose between Hash Based or File Based signing.
    Note: For file-based signing, PQC certificate support is available for ML-DSA only. For hash-based signing, PQC certificate support is not available.
    *File Types This field is displayed only when the Signing Type is set as File Based. Select one or more file types that should be signed using the signing policy. Supported file types include PS1, EXE, CAT, MSI, JS, JAR, APK, VBS, CAB, WSF, DLL, PSM1, PSD1, PS1XML, JSE, and VBE among others.
    Note: Selected file types will only be permitted for upload and signing under this policy.
    Data Center This field is displayed only when the Signing Type is set as File Based. Select the data center from the dropdown where timestamping requests will be routed. Ensure that the selected TSA URL is reachable from all servers managed under the chosen data center.
    Restriction Type Select None or between IP-based restriction or IP Range-based restriction.
    *List of IP's This field is displayed when the Restriction Type is set as IP. Enter a list of valid individual IP addresses at subnet or system level.
    *Start IP / *End IP This field is displayed when the Restriction Type is set as IP Range. Enter the start and end IP addresses, ensuring the end IP is greater than the start IP.
    Enable HSM Polling This applies to HSM-based certificates. Enable the toggle to allow the system to retry fetching the signing operation status based on the configurations defined in the signing policy, overriding the global Sign Settings.
    Note: Enable HSM Polling option is enabled by default for all existing signing policies.
    *Number Of Polls This field is displayed when the Enable HSM Polling toggle is enabled. Add the number of polls if the certificate is based on HSM. Specify the total number of polls to be conducted within the designated polling interval. The value must be an integer between 1 and 20.
    *Polling Interval This field is displayed when the Enable HSM Polling toggle is enabled. Add the Polling Interval if the certificate is based on HSM. Set the time interval between consecutive polls. The value must be an integer between 1 and 300000 milliseconds.
    Test Policy Select the checkbox to create the policy for internal testing. Enabling this option ignores all signatures associated with the policy in the license counting.
    Enable Email notification Enable the toggle button to receive email notifications and updates via email when the signing events occur.
    *: Mandatory fields
  4. (Optional step) If the Enable Email notification toggle switch is enabled then enter/select the Email Configuration details as described below.
    Table 2. Field description for the Email Configuration section
    Field name Description
    *Email Subject Enter the subject line for the email notification to identify the purpose or content of the email. Acceptable characters are letters, numbers, and spaces.
    *To Enter one or more recipients email address separated by comma.
    Event Type Choose the type of events for which notifications are required. The values are Success, Failure, or Both.
    *Required Field A multi-select dropdown field with values - Policy name, Signing Type, Key Name, IP Address, Signing Time, and Username. Select one or more values whose details are to be displayed in the mail body for comprehensive notification.
    *: Mandatory fields
  5. (Optional) Configure the Signing Quota Controls to define usage limits on signing operations for the policy.

    Signing Quota Controls allow administrators to enforce per-user limits on signing activity within a policy. Quotas can be enabled for both Hash Based and File Based signing policies.

    Note: When the Signing Quota Controls toggle is disabled, no quota restrictions are enforced for the policy. Disabling the toggle on an active policy clears all previously configured quota restrictions. If the toggle is re-enabled, the restrictions must be reconfigured.
    1. Enable the Signing Quota Controls toggle to activate quota configuration for the policy.
    2. Select the Quota Type from the available options.

      Only one quota type can be active per policy at a time. The available quota types depend on the selected Signing Type:

      • Number of signing operations: Available for both Hash Based and File Based signing policies. Limits the total number of signing operations a user can perform within the configured frequency window.
      • Number of total artifacts signed: Available only for File Based signing policies. Limits the total number of artifacts (files) of a specific file type that a user can sign within the configured frequency window.
    3. Configure the quota restriction details based on the selected quota type.
      Table 3. Field description for Number of signing operations quota
      Field name Description
      *User Select one or more user or service accounts from the dropdown.
      *Limit Specify the maximum number of signing operations allowed per user within the selected frequency window. The value must be an integer between 1 and 10,000,000.
      *Frequency Select the time window for the quota. The counter resets at the start of each calendar period. Available options:
      • Daily Resets at midnight.
      • Weekly Resets at the start of each week (Monday 00:00).
      • Monthly Resets on the 1st of each month.
      • Quarterly Resets on the 1st of each quarter.
      • Yearly Resets on the 1st of January.
      *Enforcement Behavior Select the action to take when the configured quota limit is exceeded:
      • Block signing Signing requests are blocked when the quota limit is reached. The user cannot perform further signing operations until the frequency window resets.
      • Allow with warning Signing requests continue to be processed after the quota limit is exceeded, but a warning message is returned with each signing response. An audit log entry is recorded for each warning event.
      • Allow burst, then block Signing requests are allowed beyond the base quota limit up to a configurable burst threshold. Once the burst limit is exhausted, signing is blocked until the frequency window resets.
      *Burst Percentage This field is displayed only when the Enforcement Behavior is set to Allow burst, then block. Specify the burst percentage over the base quota limit. The value must be a positive integer. For example, if the limit is 100 and the burst percentage is 20, the user can perform up to 120 signing operations before signing is blocked.
      *: Mandatory fields
      Table 4. Field description for Number of total artifacts signed quota (File Based only)
      Field name Description
      *User Select one or more user or service accounts from the dropdown.
      *File Type Select the file type from the system-defined list of supported file types (for example, EXE, MSI, JAR, APK, DLL, and others). Each file type can have its own quota configuration.
      *Count Specify the maximum number of artifacts of the selected file type that a user can sign within the selected frequency window. The value must be an integer between 1 and 10,000,000.
      *Frequency Select the time window for the quota. The counter resets at the start of each calendar period. Available options:
      • Daily Resets at midnight.
      • Weekly Resets at the start of each week (Monday 00:00).
      • Monthly Resets on the 1st of each month.
      • Quarterly Resets on the 1st of each quarter.
      • Yearly Resets on the 1st of January.
      *Enforcement Behavior Select the action to take when the configured quota limit is exceeded:
      • Block signing Signing requests for the specified file type are blocked when the quota limit is reached.
      • Allow with warning Signing requests continue to be processed after the quota limit is exceeded, but a warning message is returned with each signing response.
      • Allow burst, then block Signing requests are allowed beyond the base quota limit up to a configurable burst threshold. Once the burst limit is exhausted, signing is blocked until the frequency window resets.
      *Burst Percentage This field is displayed only when the Enforcement Behavior is set to Allow burst, then block. Specify the burst percentage over the base quota count. The value must be a positive integer.
      *: Mandatory fields
      Note: Multiple file-type quota rows can be configured for a single policy. Click Add to add additional file-type Quota Assignment.
  6. In the Map Signing Key section, select the required keys from the code signing inventory and add them to map them against a policy. If more than one signing key is mapped to a policy then the signing key should be chosen as an option in the Upload & Sign or the default signing key will be used for signing. Click the Add Key button to add the keys.
    Note: PQC certificate support is only available for ML-DSA and only file based signing is supported.
  7. In the Add-On Fields section, add meta information that needs to be collected from the signer who requests for signing. This meta information (e.g. OS version, build version, comments, description, etc.) will also be stored in the inventory along with the signed code/artifacts. Enter values in the Field Name and Field Type fields and select the Make Mandatory checkbox as required.
  8. Click Add.
    The Add-On Fields will be added in the meta information table.
  9. Click Create.
    The signing policy is created in the inventory.
    Note: Deletion of a signing policy is restricted if it is associated with a signing record.
  10. Upload and sign the code signing file with the specified file type selected during policy creation.

What to do next:

  • Upload and sign the code signing file with the specified file type selected during policy creation.