DigiCert® Software Trust Manager for Azure DevOps Pipelines
DigiCert® Software Trust Manager for Azure DevOps Pipelines enables
organizations to seamlessly integrate secure signing workflows into
Azure DevOps build and release pipelines.
This production-ready Azure DevOps extension supports Windows, Linux,
and macOS agents, offering both simplified and traditional signing
workflows to align with diverse development and release strategies.
The enhanced version 2 with SSMClientToolsSetup@2 task automates the setup of the
required client and signing tools directly within the pipeline. It
supports simple signing with no third-party signing tools required,
as well as traditional signing using tools such as SignTool,
Jarsigner, and other signing utilities through KSP and PKCS#11.
What's new in version 2
- Cross-platform support for Windows, Linux, and macOS.
- Simple signing using
smctl without third-party signing tools. Simple signing support using simpleSigningMode.
- Traditional signing with SignTool, Jarsigner, and other supported
signing utilities.
- Automatic installation and configuration of Software Trust Manager
client tools.
- SHA-256 checksum verification for downloaded tools.
- Tool caching to reduce setup time on subsequent pipeline runs.
- Automatic PKCS#11 configuration generation.
- Continued support for existing extension v1 pipelines through backward-compatible inputs.
Available tasks
SSMClientToolsSetup@2- Installs and configures Software Trust Manager client tools and optionally performs simple signing.
SSMSigningToolsSetup@1- Installs standalone signing tools for traditional signing workflows.
Supported signing approaches
Simple signing
- Uses the DigiCert Signing Manager Controller (
smctl) to sign files
directly from the pipeline.
- No third-party signing tools are required.
- Supports signing individual files and directories.
Traditional signing
- Integrates with third-party signing tools such as:
- SignTool
- Jarsigner
- jsign
- OpenSSL
- osslsigncode
- Mage
- Keytool
- NuGet
- XMLSecTool
- Supports:
Upgrade from extension v1 to extension v2
Upgrading from SSMClientToolsSetup@1 to SSMClientToolsSetup@2 is a non-breaking change and requires no modifications to existing pipelines.
- Existing pipelines continue to work without modification.
- Existing PKCS#11 configuration output variables remain unchanged.
Documentation
For installation, configuration, migration guidance, and examples, see
the Software Trust Manager documentation:
https://docs.digicert.com/en/software-trust-manager/ci-cd-integrations-and-deployment-pipelines/plugins/azure.html
Support
Contact DigiCert support for Software Trust Manager assistance.
Learn more
To learn more about Software Trust Manager, visit:
https://www.digicert.com/software-trust-manager