Self-Signed Certificates
Generate 4096-bit RSA .pfx certificates with custom CN, Org, and validity period. Exportable and PKCS#12 compliant.
The ultimate offline desktop application for developers. Generate certificates, sign executables, verify Authenticode signatures, run Pre-Flight release checks, and hash ANY file type securely.
Built with Python, cryptography, and modern Tkinter UI principles. Works offline. No telemetry.
Generate 4096-bit RSA .pfx certificates with custom CN, Org, and validity period. Exportable and PKCS#12 compliant.
Drop supported binaries (.exe, .dll, .msi, .sys, .cab, etc.) into the signing zone. One click signs with RFC 3161 timestamping.
Drop ANY file (ISO, ZIP, PDF, EXE) to instantly generate MD5, SHA1, and SHA256 checksums. Recalculates automatically after signing.
Instantly verify Authenticode signatures. View signer details, timestamp status, and trust chain validity in a clean report card.
Ensure your binary is ready for public release. Checks for valid signatures, timestamps, and detects Mark-of-the-Web (MOTW) flags.
Automatically generate GitHub-ready Markdown release notes complete with file sizes, checksums, and PowerShell verification commands.
Automatically install certificates to Windows Trusted Root & Trusted Publishers stores (requires admin).
Sign entire folders and multiple files at once with a single click, saving time on large projects.
Export ready-to-use GitHub Actions or Azure DevOps pipeline configurations for automated code signing.
Select and install existing .pfx certificates to Trusted Root & Publishers on different machines for the same signed executable.
Load existing .pfx files directly in Step 2. Auto-fills metadata and warns if the certificate is expired or expiring soon.
Use hardware tokens or HSMs by providing the certificate thumbprint. Supports all CSP/KSP providers.
No cloud dependencies. No account required. Just download and run.
Fill in Common Name and Organization. Click "Generate" to create a secure .pfx file locally.
Drop your executable into the signing zone. The app signs the file and automatically recalculates hashes to verify integrity.
Use the Verify tool to check the signature, run a Pre-Flight check (Pro), and generate Markdown release notes.
We're constantly improving. Here is a sneak peek at the powerful features arriving in the next major update.
A fully integrated, sleek dark mode toggle that dynamically themes the entire UI, including the drag-and-drop zones and hash badges, for comfortable late-night coding.
Paste an expected SHA256 hash from a download page, and the toolkit will instantly compare it, displaying a massive, color-coded EXACT MATCH or MISMATCH badge.
Choose your preferred RFC 3161 Timestamp Authority (DigiCert, Sectigo, SSL.com, GlobalSign) via a dropdown. If one TSA goes down, instantly switch to another.
Free for development. Pro for production and commercial distribution.
Self-signed certs are for development only. For public distribution, get a CA-issued code signing certificate:
Download the standard installer for easy setup on Windows 10/11.
Released August 2026 • Windows 10/11 (64-bit)
cb773dbd46e9e24dbac1a05fae09f972309d4b3026622b24a71e78b7132f2903
💡 First run? The app will auto-detect signtool.exe. If missing, install Windows SDK