Keyfactor Signum strengthens software supply chain security without slowing productivity

Ben Dewberry of Keyfactor

Independence, OH – 11 October 2022 – Keyfactorthe machine and IoT identity platform for modern enterprises, has announced the launch of Keyfactor Signum, a new code signing as-a-service platform that makes it easy for developers to sign code and containers in a secure way, without disrupting productivity.

Organisations face persistent software supply chain attacks that compromise application development pipelines, IT scripts, macros, and more. Code signing keys are high-value targets for attackers that seek to steal and compromise keys to sign malicious code disguised as trusted software. Shortcuts in the signing process often lead to sensitive keys being left exposed on build servers or developer workstations. Understanding who signed which code and in what context is critical to prevent attacks.

Keyfactor Signum solves these challenges by providing security teams with protection for code signing keys, backed by an HSM and granular signing policies while allowing developers to leverage the same native signing tools they currently use.

The CA/B Forum has issued requirements that stipulate private keys for EV code signing certificates be generated and protected in a compliant hardware crypto module. “Recent changes made by the CA/B Forum, which are scheduled to go into effect in the next 12 months, mean that organisations are required to generate and store code signing keys in a cryptographic module,” says Ben Dewberry, product manager signing & key management, Keyfactor. “Keyfactor Signum makes it easy to comply with these new requirements, without causing any disruption to developers that need to move quickly.”

Keyfactor Signum is a SaaS solution hosted and managed by Keyfactor in the cloud. Key features and benefits include:

  • Integrate with Native Tools: Keyfactor Signum integrates natively with popular signing tools like Microsoft SignTool, OpenSSL, and Jarsigner via the KSP interface for Windows and PKCS11 interface for Linux, making it transparent to developers.
  • Secure Key Storage: Sensitive signing keys are generated and stored in HSM to ensure the highest level of protection and comply with CA/B Forum Extended Validation code signing certificate requirements.
  • Policy and Governance: A simple web interface makes it easy to define who can sign what, when, and where, with complete auditability of all signing activities.
  • Authentication: Only authorised developers and admins can sign code and manage signing policies via integration with Identity Providers, making it easy to deploy rapidly throughout the organisation.

To learn more about Keyfactor Signum, click here.

Comment on this article below or via Twitter: @IoTNow_OR @jcIoTnow

RECENT ARTICLES

SES to acquire Intelsat in deal aimed at creating a multi-orbit operator

Posted on: May 1, 2024

SES and Intelsat have agreed that SES will acquire Intelsat by purchasing 100 percent of the equity of Intelsat Holdings S.a.r.l. for a cash amount of US$3.1 billion (€2.8 billion)

Read more

Arduino transforms industrial space with pen-source hardware

Posted on: April 30, 2024

Visit Automate Show 2024 (May 6-9) to discover how Arduino is transforming the industrial automation space through open-source hardware and software, providing new perspectives and unlocking opportunities across every industry. More

Read more
FEATURED IoT STORIES

What is IoT? A Beginner’s Guide

Posted on: April 5, 2023

What is IoT? IoT, or the Internet of Things, refers to the connection of everyday objects, or “things,” to the internet, allowing them to collect, transmit, and share data. This

Read more

The IoT Adoption Boom – Everything You Need to Know

Posted on: September 28, 2022

In an age when we seem to go through technology boom after technology boom, it’s hard to imagine one sticking out. However, IoT adoption, or the Internet of Things adoption,

Read more

9 IoT applications that will change everything

Posted on: September 1, 2021

Whether you are a future-minded CEO, tech-driven CEO or IT leader, you’ve come across the term IoT before. It’s often used alongside superlatives regarding how it will revolutionize the way

Read more

Which IoT Platform 2021? IoT Now Enterprise Buyers’ Guide

Posted on: August 30, 2021

There are several different parts in a complete IoT solution, all of which must work together to get the result needed, write IoT Now Enterprise Buyers’ Guide – Which IoT

Read more

CAT-M1 vs NB-IoT – examining the real differences

Posted on: June 21, 2021

As industry players look to provide the next generation of IoT connectivity, two different standards have emerged under release 13 of 3GPP – CAT-M1 and NB-IoT.

Read more

IoT and home automation: What does the future hold?

Posted on: June 10, 2020

Once a dream, home automation using iot is slowly but steadily becoming a part of daily lives around the world. In fact, it is believed that the global market for

Read more

5 challenges still facing the Internet of Things

Posted on: June 3, 2020

The Internet of Things (IoT) has quickly become a huge part of how people live, communicate and do business. All around the world, web-enabled devices are turning our world into

Read more