Code Signing Settings

Enabling HSM parallelism previously involved executing database scripts in each environment, often resulting in confusion. To streamline this process, a centralized Code Signing Settings page has been introduced with a global toggle to enable or disable HSM parallelism removing the need for manual script execution. This global configuration of Number Of Polls and Polling Interval, which are applied as default values to newly created policies. To customize these settings at the policy level, users can enable the new Enable HSM Polling toggle on the Sign Policy page, allowing policy-specific values to override the global configuration. This applies only to HSM-based certificates.
Note: This page is accessible only to admin users by default. To grant access to non-admin users, enable the corresponding ACF permission under Code Signing > Sign Settings.

To Configure HSM Parallelism in Sign Settings:

  1. Go to (Menu) > Code Signing > SIGN SETTINGS > Code Signing Settings.
    The Signing Settings page is displayed.
  2. If the Activate HSM Parallel Mode is disabled, the Number Of Polls and Polling Interval fields are dispalyed.
  3. Enter the *Number Of Polls.
    This specifies how many polling attempts should be made for certificates using HSM. The value must be an integer between 1 and 20.
  4. Enter the Polling Interval, the time (in milliseconds) between each poll.
    This defines the delay between consecutive polls. The value must be an integer between 1 and 300000 milliseconds.
  5. To enable HSM parallelism, select the Activate HSM Parallel Mode checkbox.
    When enabled, HSM parallelism handles signing operation statuses internally, improving performance and eliminating the need for manual polling. If HSM devices experience delays, you can disable this mode and configure the global polling settings for more reliable status retrieval.
  6. To enable HSM parallelism pool mode, select the Activate HSM Parallel Pool Mode checkbox.
    When you enable this option, the system pre-creates HSM sessions and reuses them from a shared pool for signing operations. This reduces connection overhead and improves throughput for high-volume workloads. Supported for Fortanix HSM devices only. To resolve session exhaustion or compatibility issues, disable this option to revert to per-operation session management.
  7. To enable HSM Deferred Password Decryption, select the Activate HSM Deferred Password Decryption checkbox.
    When you enable this option, the system defers HSM password decryption until a new session is required. If a valid Fortanix PKCS#11 session is already cached, signing proceeds without decrypting the HSM password, reducing unnecessary credential exposure. Applicable to Fortanix HSM only.
  8. Click Save.
    The Signing Settings have been saved successfully.