Self-Signed Certificates
Generate 4096-bit RSA .pfx certificates with custom CN, Org, and validity period. Exportable and PKCS#12 compliant.
This Code Signing Tool is a powerful desktop application for developers and software publishers. It automatically creates self-signed certificates, signs Windows executables, and acts as a universal file hasher for ANY file type (ISO, ZIP, etc.)—all offline, securely, and without relying on cloud services.
Built with Python, cryptography, and modern Tkinter UI principles. Works offline. No telemetry.
Generate 4096-bit RSA .pfx certificates with custom CN, Org, and validity period. Exportable and PKCS#12 compliant.
Drop supported binaries (.exe, .dll, .msi, .sys, .cab, etc.) into the signing zone. One click signs with RFC 3161 timestamping via signtool.exe.
Drop ANY file (ISO, ZIP, PDF, EXE) to instantly generate MD5, SHA1, and SHA256 checksums. Automatically recalculates hashes after signing supported binaries.
Automatically install certificates to Windows Trusted Root & Trusted Publishers stores (requires admin).
Auto-detects signtool.exe across Windows SDK, Visual Studio, and App Certification Kit paths.
Sign entire folders and multiple files at once with a single click, saving time on large projects.
Export ready-to-use GitHub Actions or Azure DevOps pipeline configurations for automated code signing.
Use hardware tokens or HSMs by providing the certificate thumbprint. Supports all CSP/KSP providers.
Deploy to other PCs - Select and install existing certificates to Trusted Root & Publishers on different machines for the same signed executable.
Load your existing .pfx certificate files directly in Step 2. Making it easy to reuse certificates for signing multiple versions of your software.
No cloud dependencies. No account required. Just download and run.
Fill in Common Name and Organization. Click "Generate" to create a secure .pfx file locally.
Drop your executable into the signing zone. The app constructs the signtool command, signs the file, and automatically recalculates hashes to verify integrity.
Unlock batch signing, CI/CD exports, and trusted store auto-installation with a one-time $29 license.
We're constantly improving. Here is a sneak peek at the powerful features arriving in the next major update.
Instantly verify Authenticode signatures. View signer details, timestamp status, and trust chain validity in a clean, easy-to-read report card.
Ensure your binary is ready for public release. Checks for valid signatures, timestamps, and detects Mark-of-the-Web (MOTW) flags to prevent SmartScreen warnings.
Automatically generate GitHub-ready Markdown release notes complete with file sizes, checksums, and PowerShell verification commands.
Free for development. Pro for production and commercial distribution.
Self-signed certs are for development only. For public distribution, get a CA-issued code signing certificate:
Download the standard installer for easy setup on Windows 10/11.
Released August 2026 • Windows 10/11 (64-bit)
662a3cbf0b8ea99940c231208bbbac82f3f51cf02ab17bebbc93b8d462f108f1
💡 First run? The app will auto-detect signtool.exe. If missing, install Windows SDK