Table of Contents
To sign Windows files with DigiCert KeyLocker and Click-to-Sign, create an API key and client certificate in DigiCert ONE, install the KeyLocker client tools, run the Click-to-Sign setup wizard, then right-click any file or folder and choose Review and sign. Your private key never leaves KeyLocker.
If you have ever kept a .pfx file on a shared build machine, you know the problem. Someone copies it, someone emails it, and a year later nobody can say how many copies exist. KeyLocker takes that file out of the picture.
Click-to-Sign adds a simple layer on top: no command line, no scripts. You pick a file in File Explorer and sign it.
This guide covers the full setup on a Windows signing machine, step by step, plus the checks and fixes that save you an afternoon later.
What Click-to-Sign is and when to use it
Click-to-Sign is a desktop tool in the KeyLocker client package. It adds a right-click option to File Explorer so you can sign without typing a command.
Under the hood it still calls SMCTL and the PKCS#11 library. You just never see them.
It fits best when:
- You sign installers or drivers by hand, a few at a time
- The person signing is not comfortable in a terminal
- You want a quick review screen before anything gets signed
It is the wrong pick for automated builds. For CI/CD pipelines, use SMCTL or a pipeline plugin instead.
One more catch: DigiCert’s current docs list Windows 10 as the supported OS for Click-to-Sign. If you run Windows 11, check the latest Click-to-Sign documentation before you build a workflow around it.
Before you start
Get these lined up first. Missing one is the usual reason setup stalls halfway.
- A DigiCert ONE account with KeyLocker enabled and a code signing certificate already in it
- Your keypair alias, which you can copy from the certificate details in DigiCert ONE
- A Windows machine where you have admin rights
- Windows SDK, only if you plan to use SignTool as the signing tool (DigiCert’s client package does not include it)
- The files you want to sign, saved somewhere with plain, simple file names
One habit worth building now: do all of this on the machine that will actually do the signing. Credentials and tool paths are set per machine.
Step 1: Create your KeyLocker API key and client certificate
KeyLocker needs two things from you before it will sign anything: an API key and a client authentication certificate. They prove the request is coming from you.
- Log in to DigiCert ONE.
- Open the Manager menu at the top right and choose KeyLocker.
- Click Get started, then Create, and follow the prompts through to Finish.
- Under Create your API token, click Next and save the token.
- Download the client certificate and note the password it asks you to set.
Treat both like passwords. Keep them out of shared drives, chat threads and source control. If either one leaks, someone else can request signatures against your certificate.
Step 2: Install the KeyLocker client tools
Back on the KeyLocker page, find the section for setting up the client tools and click Download. You will get the Windows installer, named Keylockertools-windows-x64.
Run it and click Install. It puts SMCTL, Click-to-Sign and the PKCS#11 library on the machine. The default folder is:
C:\Program Files\DigiCert\DigiCert KeyLocker Tools\
Leave it there. Click-to-Sign looks for its tools in that folder.
Add the tools folder to PATH
Open the Windows search box, type environment variables, and open the editor. Select the Path variable, click Edit, then New, and paste the folder path above. Click OK on each dialog.
Save your credentials
Next, tell SMCTL who you are. From a command prompt, run:
smctl credentials save <API token> <client certificate password>
Then confirm the connection:
smctl healthcheck
If the check passes, the machine can talk to KeyLocker and you can move on. If it fails, fix it now. Everything after this step depends on it.
Step 3: Install and configure Click-to-Sign
The Click-to-Sign installer sits in the same tools folder, named DigiCert_Click_to_sign.msi.
- Run the installer and choose an install folder. The default is C:\Program Files\DigiCert\Click-to-sign.
- Click Install.
- Leave Launch Click to sign ticked and click Finish.
- When the setup wizard opens, click Next.
- Confirm the PKCS#11 config path. The default is C:\Program Files\DigiCert\DigiCert KeyLocker Tools\pkcs11properties.cfg.
- Click OK, then Next, and finish the wizard.
The wizard is also where you pick your default keypair and certificate. You can change those later from the right-click menu under DigiCert Click-to-sign, then Settings.
Step 4: Sign a file or a folder
This is the part you will repeat every release, and it takes a few clicks.
Sign one file
- Open File Explorer and right-click the file.
- Choose DigiCert Click-to-sign.
- Pick Sign now to sign straight away, or Review and sign to see the details first.
- If you chose review, click Sign when you are happy.
Give it a few seconds. The request goes out to KeyLocker and the signed file comes back.
Sign a whole folder
Right-click the folder instead of a file and follow the same menu. Expect it to take a few minutes if the folder is large.
One thing to watch
Click-to-Sign will not sign files whose names contain certain special characters. If a file gets skipped, rename it with letters, numbers and underscores and run it again.
Step 5: Check that the signature took
Never assume. Look.
The quickest check is in Windows itself. Right-click the signed file, open Properties, and look for a Digital Signatures tab. Select the signature, click Details, and confirm it shows a valid signature with a timestamp.
Prefer the command line? Either of these works:
signtool verify /pa <path to signed file>
smctl sign verify --input <path to signed file>
The timestamp matters. It keeps the signature valid after the certificate itself expires, so do not skip it.
Troubleshooting
Most failures trace back to one of four things: the PATH, the credentials, SignTool, or a file name. Start with the symptom.
- No DigiCert Click-to-sign option in the right-click menu. Confirm the tools sit in the default KeyLocker Tools folder and that the folder is on PATH. Then sign out of Windows and back in, or restart File Explorer.
- Authentication errors. Re-run smctl credentials save with the correct API token and client certificate password, then run smctl healthcheck. A mistyped password is the most common cause.
- SignTool not found. DigiCert’s package does not include it. Install the Windows SDK and add the folder holding signtool.exe to PATH. The x64 folder sits under the Windows Kits directory, in the bin folder for your SDK version.
- A file was skipped. Check the name for special characters and rename it.
- Still stuck. DigiCert keeps a dedicated Click-to-Sign troubleshooting article linked from its setup page.
Click-to-Sign, SMCTL or SignTool: which one?
All three sign with the same KeyLocker keypair. They differ in how you drive them.
| Tool | Best for | Interface | What it needs |
|---|---|---|---|
| Click-to-Sign | Manual signing by people who prefer a UI | Right-click in File Explorer | SMCTL, PKCS#11 library, Windows 10 |
| SMCTL | Scripts, batches and most automated workflows | Command line | KeyLocker client tools only |
| SignTool | Teams already built around Microsoft’s signing tool | Command line | Windows SDK and the DigiCert KSP |
DigiCert points most users to SMCTL as the default. It has fewer dependencies and is easier to configure, though its simple signing mode supports fewer file types. Click-to-Sign is the friendlier front door. SignTool makes sense when your existing build scripts already call it.
FAQ
Does Click-to-Sign work on Windows 11? DigiCert’s docs currently name Windows 10 as the compatible system. Check the live documentation before relying on it for Windows 11.
Where does my private key live? In KeyLocker. It is not stored on the signing machine, which is the main reason to use it over a local .pfx file.
Can I sign a whole folder at once? Yes. Right-click the folder, choose DigiCert Click-to-sign, then Review and sign.
Do I need SignTool? Only if you choose it as your signing tool. It comes with the Windows SDK, not with DigiCert’s client package.
Can I use Click-to-Sign in a build pipeline? It is built for manual use. For pipelines, use SMCTL or DigiCert’s CI/CD integrations.
What if I change my certificate later? Open DigiCert Click-to-sign, then Settings, from the right-click menu and pick the new keypair.
Wrap-up
Setup is a one-time job: API key and client certificate, client tools, Click-to-Sign wizard. After that, signing is a right-click.
Run smctl healthcheck whenever something feels off, and verify every signed file before it ships. Those two habits catch most problems early.
If you later move to automated builds, the same keypair works with SMCTL, so nothing you set up here is wasted.