Machine Identities
Code Sign Manager
Code Sign Manager protects the keys used to sign software and brings code signing under central policy. It was formerly known as Venafi CodeSign Protect.
What it is
Code Sign Manager keeps code-signing keys in a protected store and never exposes them directly to developers or build systems. Signing happens through a controlled service, so the right people and pipelines can sign code without holding the private keys. Each signing action follows policy and is recorded.
Key capabilities
- Stores code-signing keys in a protected, central location.
- Lets developers and pipelines sign code without direct access to private keys.
- Enforces approval and policy on who can sign what.
- Logs every signing action for audit.
- Supports common signing tools and formats.
Who it’s for
Code Sign Manager fits software teams and organizations that ship signed code, drivers, or firmware. It helps development and security teams prevent key misuse while keeping signing fast for trusted users.