{"id":208,"date":"2026-09-26T10:43:17","date_gmt":"2026-09-26T10:43:17","guid":{"rendered":"https:\/\/codesigncert.com\/resources"},"modified":"2026-09-26T10:43:17","modified_gmt":"2026-09-26T10:43:17","slug":"google-kms-digicert-code-signing-2026-setup-guide","status":"publish","type":"resources","link":"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide","title":{"rendered":"Google KMS + DigiCert Code Signing: 2026 Setup Guide"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 ez-toc-wrap-right counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Why_the_delivery_method_isnt_a_checkbox_anymore\" >Why the delivery method isn&#8217;t a checkbox anymore<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#What_Google_Cloud_KMS_is_actually_doing_in_this_setup\" >What Google Cloud KMS is actually doing in this setup<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Before_you_start\" >Before you start<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Step_1_Create_the_key_ring_and_signing_key\" >Step 1: Create the key ring and signing key<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Step_2_Generate_the_CSR_and_key_attestation\" >Step 2: Generate the CSR and key attestation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Step_3_Complete_DigiCert_certificate_enrollment\" >Step 3: Complete DigiCert certificate enrollment<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Step_4_Install_the_Google_Cloud_KMS_CNG_provider\" >Step 4: Install the Google Cloud KMS CNG provider<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Step_5_Sign_your_executable_with_SignTool\" >Step 5: Sign your executable with SignTool<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Confirming_the_signature_actually_holds\" >Confirming the signature actually holds<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Where_this_setup_actually_breaks\" >Where this setup actually breaks<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#What_it_actually_costs\" >What it actually costs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#Questions_people_actually_ask_before_starting_this\" >Questions people actually ask before starting this<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"#\" data-href=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\/#The_takeaway\" >The takeaway<\/a><\/li><\/ul><\/nav><\/div>\n<p>If your code signing key still lives on a USB token sitting in someone&#8217;s desk drawer, you&#8217;re already out of step with where this industry is headed. Since June 2023, the CA\/Browser Forum has required that private keys for publicly trusted code signing certificates sit on FIPS 140-2 Level 3 hardware. A physical token satisfies that. So does a cloud HSM, and for teams already running on Google Cloud, KMS is the more sensible answer than shipping a token to every build machine.<\/p>\n<p>This guide walks through pairing DigiCert code signing certificates with Google Cloud KMS end to end: generating the key, getting DigiCert to issue against it, installing the CNG provider, and actually signing a binary with SignTool. No filler, no vendor pitch \u2014 just the sequence that works and the parts that trip people up.<\/p>\n<h2 id=\"why-the-delivery-method-isnt-a-checkbox-anymore\"><span class=\"ez-toc-section\" id=\"Why_the_delivery_method_isnt_a_checkbox_anymore\"><\/span>Why the delivery method isn&#8217;t a checkbox anymore<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Before the 2023 rule change, most developers stored their code signing private key as a .pfx file on the build server. That was the whole security model. The CA\/Browser Forum killed that practice for a reason: a stolen .pfx file is a signed malware campaign waiting to happen, and it had already happened more than once.<\/p>\n<p>Hardware-backed storage means the private key material never exists in exportable form. It&#8217;s generated inside the HSM boundary and stays there. When you sign, you&#8217;re not pulling the key out \u2014 you&#8217;re sending a hash to the HSM and getting a signature back. The key itself never leaves.<\/p>\n<p>This is exactly what Google Cloud KMS gives you when you choose an HSM protection level, and it&#8217;s why DigiCert lists it as a supported &#8220;Install on Existing HSM&#8221; delivery method. You&#8217;re not bolting on compliance after the fact. You&#8217;re building the certificate against hardware DigiCert already trusts.<\/p>\n<h2 id=\"what-google-cloud-kms-is-actually-doing-in-this-setup\"><span class=\"ez-toc-section\" id=\"What_Google_Cloud_KMS_is_actually_doing_in_this_setup\"><\/span>What Google Cloud KMS is actually doing in this setup<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Strip away the marketing language and Cloud KMS is a key vault with a signing API sitting in front of it. You create a key ring (a folder, essentially), generate an asymmetric signing key inside it at the HSM protection level, and Google stores that key in a FIPS 140-2 Level 3 certified module across its infrastructure.<\/p>\n<p>The part that matters for code signing: Cloud KMS never hands you the private key. Not through the console, not through the API, not ever. What you get instead is a resource path \u2014 something like <code spellcheck=\"false\">projects\/your-project\/locations\/us\/keyRings\/code-signing-ring\/cryptoKeys\/signing-key\/cryptoKeyVersions\/1<\/code> \u2014 and permission to ask that key to sign things on your behalf.<\/p>\n<p>DigiCert&#8217;s role doesn&#8217;t change in this arrangement. It still validates your organization, still issues the certificate, still runs the whole chain of trust back to its root. The only thing that moves is where the private key physically sits. Instead of a token plugged into a laptop, it&#8217;s a key version inside a Google-managed HSM cluster, reachable from wherever your build pipeline runs.<\/p>\n<h2 id=\"before-you-start\"><span class=\"ez-toc-section\" id=\"Before_you_start\"><\/span>Before you start<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Have these ready before opening a terminal \u2014 half the frustration with this setup comes from starting the certificate request before the key exists.<\/p>\n<ul>\n<li>A Google Cloud project with billing enabled and the Cloud KMS API turned on<\/li>\n<li>IAM permissions to create key rings and keys \u2014 Cloud KMS Admin at minimum, plus Cloud KMS CryptoKey Signer\/Verifier for whichever identity will actually sign<\/li>\n<li>A DigiCert account able to place a Code Signing Certificate order with &#8220;Install on Existing HSM&#8221; (or equivalent cloud HSM) as the delivery method<\/li>\n<li>Organization validation already completed, or ready to complete \u2014 DigiCert still needs to confirm you&#8217;re a legitimate business before issuing anything<\/li>\n<li>A Windows machine with the Windows SDK installed, for SignTool<\/li>\n<li>Admin rights on that Windows machine to install the Google Cloud KMS CNG provider<\/li>\n<\/ul>\n<p>One more thing worth deciding upfront: RSA or EC. SignTool combined with the Google Cloud KMS CNG provider does not support EC keys \u2014 you need RSA, and 3072-bit is the safe default if your signing tool doesn&#8217;t specify otherwise.<\/p>\n<h2 id=\"step-1-create-the-key-ring-and-signing-key\"><span class=\"ez-toc-section\" id=\"Step_1_Create_the_key_ring_and_signing_key\"><\/span>Step 1: Create the key ring and signing key<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Everything starts in Cloud KMS. Pick a location \u2014 <code spellcheck=\"false\">us<\/code> or <code spellcheck=\"false\">global<\/code> both work, but keep it consistent with wherever your build infrastructure lives, since cross-region calls add latency to every sign operation.<\/p>\n<p>Create the key ring first:<\/p>\n<pre spellcheck=\"false\"><code>gcloud kms keyrings create code-signing-ring \\\r\n  --location us<\/code><\/pre>\n<p>Then create the key itself, set to the HSM protection level and asymmetric signing purpose:<\/p>\n<pre spellcheck=\"false\"><code>gcloud kms keys create code-signing-key \\\r\n  --location us \\\r\n  --keyring code-signing-ring \\\r\n  --purpose asymmetric-signing \\\r\n  --default-algorithm rsa-sign-pkcs1-3072-sha256 \\\r\n  --protection-level hsm<\/code><\/pre>\n<p>That last flag is the one to double-check. <code spellcheck=\"false\">--protection-level hsm<\/code> is what makes this a FIPS 140-2 Level 3 key rather than a software-backed one. Leave it out and you&#8217;ll get a key that works fine for testing but won&#8217;t satisfy DigiCert&#8217;s hardware requirement for the certificate you&#8217;re about to request.<\/p>\n<h2 id=\"step-2-generate-the-csr-and-key-attestation\"><span class=\"ez-toc-section\" id=\"Step_2_Generate_the_CSR_and_key_attestation\"><\/span>Step 2: Generate the CSR and key attestation<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>With the key created, you need two things from it: a certificate signing request DigiCert can process, and a key attestation proving the key genuinely lives on HSM-backed hardware. DigiCert won&#8217;t take your word for it \u2014 the attestation is what closes that gap.<\/p>\n<p>Google Cloud gives you two attestation formats. Download the one packaged as a <code spellcheck=\"false\">.zip<\/code> file, not the PEM version. This trips up more people than anything else in this process \u2014 DigiCert&#8217;s intake specifically wants the zip, and a PEM upload will bounce back as invalid every time.<\/p>\n<p>For the CSR itself, you have two practical routes: use the PKCS#11 library Google provides (set the <code spellcheck=\"false\">KMS_PKCS11_CONFIG<\/code> environment variable to point at a YAML file describing your key ring), or generate it through a signing tool that already understands Cloud KMS resource paths, like Jsign. Either way, the CSR needs the Code Signing extended key usage set explicitly \u2014 most OpenSSL configs default to server auth, and that certificate won&#8217;t work for Authenticode signing.<\/p>\n<h2 id=\"step-3-complete-digicert-certificate-enrollment\"><span class=\"ez-toc-section\" id=\"Step_3_Complete_DigiCert_certificate_enrollment\"><\/span>Step 3: Complete DigiCert certificate enrollment<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Inside DigiCert&#8217;s CertCentral portal, place the code signing certificate order and select the HSM-based delivery method \u2014 worded as &#8220;Install on Existing HSM&#8221; or similar, depending on which product tier you&#8217;re on. Upload the CSR and the attestation zip from the previous step when prompted.<\/p>\n<p>From here it&#8217;s DigiCert&#8217;s standard validation process, and it moves at the speed of your organization&#8217;s paperwork, not the technology. Expect a call or email verifying the business, confirming the requester has authority to sign on the organization&#8217;s behalf, and possibly a duns number or equivalent business registry check if this is a new account.<\/p>\n<p>Once validation clears, DigiCert issues the certificate against the public key from your CSR. You&#8217;ll receive the certificate as a <code spellcheck=\"false\">.crt<\/code> or <code spellcheck=\"false\">.cer<\/code> file \u2014 this is the public certificate, not a keystore, since your private key was never exported in the first place. Save it somewhere your signing tool can reach it.<\/p>\n<h2 id=\"step-4-install-the-google-cloud-kms-cng-provider\"><span class=\"ez-toc-section\" id=\"Step_4_Install_the_Google_Cloud_KMS_CNG_provider\"><\/span>Step 4: Install the Google Cloud KMS CNG provider<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>On the Windows machine that will actually run SignTool, download and install the Google Cloud KMS CNG provider using the <code spellcheck=\"false\">.msi<\/code> installer from Google&#8217;s release page. This registers a Key Storage Provider named &#8220;Google Cloud KMS Provider&#8221; inside Windows, which is how SignTool learns to route signing requests to Cloud KMS instead of a local certificate store.<\/p>\n<p>After installing, authenticate the machine so it can actually call the KMS API. For a workstation or a one-off signing box, that usually means:<\/p>\n<pre spellcheck=\"false\"><code>gcloud auth application-default login<\/code><\/pre>\n<p>For a CI\/CD runner, skip the interactive login and attach a service account instead \u2014 this is the setup you want for GitHub Actions, Azure DevOps, or any build agent that runs unattended. Grant that service account the Cloud KMS CryptoKey Signer\/Verifier role, scoped to the specific key, not the whole project. There&#8217;s no reason a build agent needs permission to touch every key in your KMS instance.<\/p>\n<h2 id=\"step-5-sign-your-executable-with-signtool\"><span class=\"ez-toc-section\" id=\"Step_5_Sign_your_executable_with_SignTool\"><\/span>Step 5: Sign your executable with SignTool<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This is the payoff step, and once it&#8217;s configured it looks almost identical to signing with a local certificate. The difference is two extra flags telling SignTool which CNG provider to use and which KMS key resource to sign against.<\/p>\n<pre spellcheck=\"false\"><code>signtool sign \/v \/debug ^\r\n  \/fd sha256 ^\r\n  \/tr http:\/\/timestamp.digicert.com \/td sha256 ^\r\n  \/f \"C:\\certs\\mycodesigningcert.crt\" ^\r\n  \/csp \"Google Cloud KMS Provider\" ^\r\n  \/kc \"projects\/PROJECT_ID\/locations\/us\/keyRings\/code-signing-ring\/cryptoKeys\/code-signing-key\/cryptoKeyVersions\/1\" ^\r\n  \"C:\\build\\MyApplication.exe\"<\/code><\/pre>\n<p>A few flags worth explaining rather than just copying: <code spellcheck=\"false\">\/fd sha256<\/code> sets the file digest algorithm \u2014 don&#8217;t drop below sha256, Windows SmartScreen and most modern OSes penalize weaker hashes. <code spellcheck=\"false\">\/tr<\/code> and <code spellcheck=\"false\">\/td<\/code> point to a timestamp authority, which matters more than people think: without it, your signature becomes invalid the moment the certificate expires, even on software signed years earlier. <code spellcheck=\"false\">\/kc<\/code> is the full resource path to the specific key version \u2014 get one character wrong here and SignTool fails with a generic &#8220;provider error&#8221; that gives you no clue what actually went wrong.<\/p>\n<p>Run it, and if everything&#8217;s wired up correctly, SignTool reports success and the binary now carries a valid Authenticode signature backed by a key that has never touched local disk.<\/p>\n<h2 id=\"confirming-the-signature-actually-holds\"><span class=\"ez-toc-section\" id=\"Confirming_the_signature_actually_holds\"><\/span>Confirming the signature actually holds<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Don&#8217;t take SignTool&#8217;s success message as the final word \u2014 verify it separately, especially the first time you run this pipeline end to end.<\/p>\n<pre spellcheck=\"false\"><code>signtool verify \/v \/pa \"C:\\build\\MyApplication.exe\"<\/code><\/pre>\n<p>This checks the full chain: your certificate, the intermediate DigiCert Trusted G4 Code Signing CA, and the DigiCert Trusted Root G4 at the top. It also confirms the timestamp is present and valid. If the chain check fails but the signature itself looks fine, it&#8217;s usually a missing intermediate certificate in the local store rather than a problem with the KMS side of things.<\/p>\n<p>Worth doing once: right-click the signed file in Windows Explorer, open Properties, and check the Digital Signatures tab. Seeing the publisher name and a valid timestamp there is the sanity check that matters to anyone downstream who isn&#8217;t going to run signtool verify themselves.<\/p>\n<h2 id=\"where-this-setup-actually-breaks\"><span class=\"ez-toc-section\" id=\"Where_this_setup_actually_breaks\"><\/span>Where this setup actually breaks<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Most problems here aren&#8217;t Cloud KMS problems or DigiCert problems \u2014 they&#8217;re the handoff between the two, or a Windows configuration detail nobody documents clearly.<\/p>\n<table>\n<colgroup>\n<col \/>\n<col \/>\n<col \/><\/colgroup>\n<tbody>\n<tr>\n<th colspan=\"1\" rowspan=\"1\">Symptom<\/th>\n<th colspan=\"1\" rowspan=\"1\">Usual cause<\/th>\n<th colspan=\"1\" rowspan=\"1\">Fix<\/th>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\">SignTool can&#8217;t find the certificate even though it&#8217;s in the Windows cert store<\/td>\n<td colspan=\"1\" rowspan=\"1\">SignTool looks for certs paired with the CNG provider, not the general cert store<\/td>\n<td colspan=\"1\" rowspan=\"1\">Reference the .crt file directly with <code spellcheck=\"false\">\/f<\/code>, don&#8217;t rely on <code spellcheck=\"false\">\/n<\/code> or <code spellcheck=\"false\">\/s<\/code> store lookups<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\">&#8220;Provider error&#8221; with no detail<\/td>\n<td colspan=\"1\" rowspan=\"1\">Wrong resource path in <code spellcheck=\"false\">\/kc<\/code>, or the key version was destroyed\/disabled<\/td>\n<td colspan=\"1\" rowspan=\"1\">Re-check the full path against <code spellcheck=\"false\">gcloud kms keys versions list<\/code>, confirm the version state is ENABLED<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\">DigiCert rejects the attestation upload<\/td>\n<td colspan=\"1\" rowspan=\"1\">Uploaded the PEM attestation instead of the zip<\/td>\n<td colspan=\"1\" rowspan=\"1\">Re-download the attestation and confirm it&#8217;s the <code spellcheck=\"false\">.zip<\/code> format before resubmitting<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\">SignTool fails specifically with EC keys<\/td>\n<td colspan=\"1\" rowspan=\"1\">The CNG provider doesn&#8217;t support EC keys for SignTool workflows<\/td>\n<td colspan=\"1\" rowspan=\"1\">Regenerate the key as RSA 3072-bit and re-run certificate enrollment<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\">Signature verifies but shows no timestamp<\/td>\n<td colspan=\"1\" rowspan=\"1\"><code spellcheck=\"false\">\/tr<\/code> flag omitted or timestamp server unreachable<\/td>\n<td colspan=\"1\" rowspan=\"1\">Add <code spellcheck=\"false\">\/tr<\/code> and <code spellcheck=\"false\">\/td sha256<\/code>, confirm outbound HTTPS access from the signing machine<\/td>\n<\/tr>\n<tr>\n<td colspan=\"1\" rowspan=\"1\">Works on one machine, fails on a build agent<\/td>\n<td colspan=\"1\" rowspan=\"1\">Service account missing the CryptoKey Signer\/Verifier role on that specific key<\/td>\n<td colspan=\"1\" rowspan=\"1\">Grant the role scoped to the key resource, not just the project<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"what-it-actually-costs\"><span class=\"ez-toc-section\" id=\"What_it_actually_costs\"><\/span>What it actually costs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Cloud KMS pricing is usage-based and, for most teams, close to a rounding error compared to the certificate itself. An HSM-backed key runs roughly $2.50 per month, plus a small per-operation charge for signing \u2014 commonly cited around $0.03 to $0.06 per 10,000 asymmetric signing operations, depending on the algorithm and region.<\/p>\n<p>Unless you&#8217;re signing thousands of builds daily, expect the KMS portion of this setup to land in the range of a few dollars a month. The real cost driver remains the DigiCert code signing certificate itself, which is priced the same whether you deliver it to a hardware token or to a cloud HSM. The delivery method changes your operational overhead, not your certificate invoice.<\/p>\n<h2 id=\"questions-people-actually-ask-before-starting-this\"><span class=\"ez-toc-section\" id=\"Questions_people_actually_ask_before_starting_this\"><\/span>Questions people actually ask before starting this<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>Can I use Google Cloud KMS with a certificate I already own, or does DigiCert have to reissue it?<\/strong> A certificate already bound to a different key can&#8217;t simply be pointed at a new one. You&#8217;ll generate a new key in Cloud KMS, submit a fresh CSR, and DigiCert reissues against that key. Your existing certificate&#8217;s validity period doesn&#8217;t carry over automatically \u2014 check with DigiCert support on reissuance terms for your specific order.<\/p>\n<p><strong>Does this work for EV code signing certificates, not just OV?<\/strong> Yes, DigiCert supports both OV and EV code signing certificates delivered to Google Cloud KMS. EV adds stricter identity validation on DigiCert&#8217;s side before issuance, but the KMS setup itself doesn&#8217;t change.<\/p>\n<p><strong>Do I need a dedicated Cloud HSM cluster, or is a KMS key with HSM protection level enough?<\/strong> A KMS key set to the HSM protection level is sufficient. You don&#8217;t need to stand up a separate Cloud HSM cluster \u2014 that&#8217;s a different, more expensive product meant for other use cases.<\/p>\n<p><strong>Can I sign on macOS or Linux without the CNG provider?<\/strong> The CNG provider is Windows-specific, since it plugs into Microsoft&#8217;s Cryptography API. On macOS or Linux, tools like Jsign or the PKCS#11 library talk to Cloud KMS directly without needing a Windows-only component.<\/p>\n<p><strong>What happens if I lose access to the Google Cloud project holding the key?<\/strong> Your signature stays valid on already-signed binaries, since verification only needs the public certificate and the CA chain. But you lose the ability to sign new code until access is restored, so IAM redundancy on who can manage that key ring is worth planning for early.<\/p>\n<h2 id=\"the-takeaway\"><span class=\"ez-toc-section\" id=\"The_takeaway\"><\/span>The takeaway<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Hardware-backed key storage stopped being optional in 2023, and it isn&#8217;t going back. Pairing DigiCert with Google Cloud KMS gets you compliant without adding a physical token to your supply chain \u2014 and once the CNG provider is installed and the IAM roles are set correctly, signing a build looks exactly like it always did, just with a different <code spellcheck=\"false\">\/csp<\/code> flag.<\/p>\n<p>The setup takes an afternoon the first time. After that, it&#8217;s one command in a build script, same as it&#8217;s always been.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If your code signing key still lives on a USB token sitting in someone&#8217;s desk drawer, you&#8217;re already out of step with where this industry is&hellip;<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"resources_category":[52],"class_list":["post-208","resources","type-resources","status-publish","hentry","resources_category-code-signing-resources"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Google KMS + DigiCert Code Signing: 2026 Setup Guide<\/title>\n<meta name=\"description\" content=\"Set up DigiCert code signing with Google Cloud KMS: create the key, get the CSR issued, install the CNG provider, and sign with SignTool.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google KMS + DigiCert Code Signing: 2026 Setup Guide\" \/>\n<meta property=\"og:description\" content=\"Set up DigiCert code signing with Google Cloud KMS: create the key, get the CSR issued, install the CNG provider, and sign with SignTool.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide\" \/>\n<meta property=\"og:site_name\" content=\"CodeSignCert\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/codesigncert\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@codesigncert\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/google-kms-digicert-code-signing-2026-setup-guide\",\"url\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/google-kms-digicert-code-signing-2026-setup-guide\",\"name\":\"Google KMS + DigiCert Code Signing: 2026 Setup Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#website\"},\"datePublished\":\"2026-09-26T10:43:17+00:00\",\"description\":\"Set up DigiCert code signing with Google Cloud KMS: create the key, get the CSR issued, install the CNG provider, and sign with SignTool.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/google-kms-digicert-code-signing-2026-setup-guide#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/codesigncert.com\\\/resources\\\/google-kms-digicert-code-signing-2026-setup-guide\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/resources\\\/google-kms-digicert-code-signing-2026-setup-guide#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Resources\",\"item\":\"https:\\\/\\\/codesigncert.com\\\/?post_type=resources\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Google KMS + DigiCert Code Signing: 2026 Setup Guide\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/\",\"name\":\"CodeSignCert\",\"description\":\"All in One Code Signing Certificate Store\",\"alternateName\":\"Code Sign Cert\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/codesigncert.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Google KMS + DigiCert Code Signing: 2026 Setup Guide","description":"Set up DigiCert code signing with Google Cloud KMS: create the key, get the CSR issued, install the CNG provider, and sign with SignTool.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Google KMS + DigiCert Code Signing: 2026 Setup Guide","og_description":"Set up DigiCert code signing with Google Cloud KMS: create the key, get the CSR issued, install the CNG provider, and sign with SignTool.","og_url":"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide","og_site_name":"CodeSignCert","article_publisher":"https:\/\/www.facebook.com\/codesigncert","twitter_card":"summary_large_image","twitter_site":"@codesigncert","twitter_misc":{"Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide","url":"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide","name":"Google KMS + DigiCert Code Signing: 2026 Setup Guide","isPartOf":{"@id":"https:\/\/codesigncert.com\/blog\/#website"},"datePublished":"2026-09-26T10:43:17+00:00","description":"Set up DigiCert code signing with Google Cloud KMS: create the key, get the CSR issued, install the CNG provider, and sign with SignTool.","breadcrumb":{"@id":"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/codesigncert.com\/resources\/google-kms-digicert-code-signing-2026-setup-guide#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/codesigncert.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Resources","item":"https:\/\/codesigncert.com\/?post_type=resources"},{"@type":"ListItem","position":3,"name":"Google KMS + DigiCert Code Signing: 2026 Setup Guide"}]},{"@type":"WebSite","@id":"https:\/\/codesigncert.com\/blog\/#website","url":"https:\/\/codesigncert.com\/blog\/","name":"CodeSignCert","description":"All in One Code Signing Certificate Store","alternateName":"Code Sign Cert","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/codesigncert.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/resources\/208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/resources"}],"about":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/types\/resources"}],"wp:attachment":[{"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/media?parent=208"}],"wp:term":[{"taxonomy":"resources_category","embeddable":true,"href":"https:\/\/codesigncert.com\/blog\/wp-json\/wp\/v2\/resources_category?post=208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}