hero-faq-1

FAQs

Does code signing work on macOS and Linux?

Yes for general signing of cross-platform binaries, including .jar files and many container formats. macOS App Store distribution requires a separate Apple Developer ID program; Linux signing is less standardized but supported across most package formats.

Copy Link

How long does code signing issuance take?

1–7 business days depending on the CA and validation level. EV usually takes longer than OV because the organization vetting is more involved, so plan extra time on a tight release deadline.

Copy Link

Which certificate do I need for Windows kernel-mode drivers?

Any EV code signing certificate. Microsoft’s WHQL portal and attestation signing flow both reject non-EV certificates outright.

Copy Link

Can I get a free code signing certificate?

No publicly-trusted CA issues them. The full reasoning and the cheapest paid alternatives are in the Why Free Code Signing Isn’t Realistic section above.

Copy Link

How long is a code signing certificate valid?

Maximum 460 days per issuance under current rules. Always sign with a timestamping authority (DigiCert’s tsa.digicert.com or Sectigo’s timestamp.sectigo.com) so binaries stay trusted past expiration. Full context in the 460-Day Validity section above.

Copy Link

Do I need a hardware token for code signing?

A hardware token is one of three options. Cloud signing services such as DigiCert KeyLocker and SSL.com eSigner skip the physical token entirely: the key sits in a CA-managed HSM and you sign over an API, which works well for CI/CD. See the hardware delivery section above.

Copy Link

What’s the difference between OV and EV?

EV vetting typically takes 3–5 business days longer than OV, and only EV qualifies for kernel-mode driver signing. Pricing, identity checks, and the SmartScreen behavior comparison are all in the OV vs EV section above.

Copy Link

What is a code signing certificate?

It’s an X.509 certificate that lets a publisher attach a verifiable digital signature to software. Unlike a CSR (just the order request submitted to the CA), the issued certificate binds a vetted identity to a public key that operating systems use to confirm a file’s origin.

Copy Link

Does SSL Dragon offer a refund if I buy the wrong certificate?

Yes. A 25-day money-back guarantee applies to every single-domain certificate. The SSL Dragon support team can also help you reissue or switch to a different certificate type (for example, moving from single-domain to wildcard) before issuance if your needs change.

Copy Link

How long is a single domain SSL certificate valid?

Each issued certificate is valid for up to 200 days under the CA/Browser Forum rules in effect since March 15, 2026. SSL Dragon’s subscription terms (running from one to three years) cover the full purchase period regardless of how many reissuances the lifespan cap requires. Your price is locked even though each individual certificate respects the current 200-day limit.

Copy Link