Skip to content
| Marketplace
Sign in
Azure DevOps>Azure Pipelines>Code signing with Software Trust Manager
Code signing with Software Trust Manager

Code signing with Software Trust Manager

DigiCert

digicert.com
|
1,500 installs
| (1) | Free
Install and setup DigiCert ONE Software Trust Manager client tools.
Get it free

DigiCert® Software Trust Manager for Azure DevOps Pipelines

DigiCert® Software Trust Manager for Azure DevOps Pipelines enables organizations to seamlessly integrate secure signing workflows into Azure DevOps build and release pipelines.

This production-ready Azure DevOps extension supports Windows, Linux, and macOS agents, offering both simplified and traditional signing workflows to align with diverse development and release strategies.

The enhanced version 2 with SSMClientToolsSetup@2 task automates the setup of the required client and signing tools directly within the pipeline. It supports simple signing with no third-party signing tools required, as well as traditional signing using tools such as SignTool, Jarsigner, and other signing utilities through KSP and PKCS#11.

What's new in version 2

  • Cross-platform support for Windows, Linux, and macOS.
  • Simple signing using smctl without third-party signing tools. Simple signing support using simpleSigningMode.
  • Traditional signing with SignTool, Jarsigner, and other supported signing utilities.
  • Automatic installation and configuration of Software Trust Manager client tools.
  • SHA-256 checksum verification for downloaded tools.
  • Tool caching to reduce setup time on subsequent pipeline runs.
  • Automatic PKCS#11 configuration generation.
  • Continued support for existing extension v1 pipelines through backward-compatible inputs.

Available tasks

  • SSMClientToolsSetup@2- Installs and configures Software Trust Manager client tools and optionally performs simple signing.
  • SSMSigningToolsSetup@1- Installs standalone signing tools for traditional signing workflows.

Supported signing approaches

Simple signing

  • Uses the DigiCert Signing Manager Controller (smctl) to sign files directly from the pipeline.
  • No third-party signing tools are required.
  • Supports signing individual files and directories.

Traditional signing

  • Integrates with third-party signing tools such as:
    • SignTool
    • Jarsigner
    • jsign
    • OpenSSL
    • osslsigncode
    • Mage
    • Keytool
    • NuGet
    • XMLSecTool
  • Supports:
    • KSP
    • PKCS#11

Upgrade from extension v1 to extension v2

Upgrading from SSMClientToolsSetup@1 to SSMClientToolsSetup@2 is a non-breaking change and requires no modifications to existing pipelines.

  • Existing pipelines continue to work without modification.
  • Existing PKCS#11 configuration output variables remain unchanged.

Documentation

For installation, configuration, migration guidance, and examples, see the Software Trust Manager documentation:

https://docs.digicert.com/en/software-trust-manager/ci-cd-integrations-and-deployment-pipelines/plugins/azure.html

Support

Contact DigiCert support for Software Trust Manager assistance.

Learn more

To learn more about Software Trust Manager, visit:

https://www.digicert.com/software-trust-manager

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft