PFX files are no longer available for Code Signing certificates. What are the other options?
Starting 06/01/2023, PFX files are no longer available for Code Signing certificates.
Modern standards require that the private keys for code signing certificates be generated and stored in secure environments.
This typically means using hardware devices such as HSMs, smart cards, or secure USB tokens.
Generating private keys on these devices ensures that the key cannot be extracted or exported, thereby preventing the issuance of certificates in PFX format.
Sectigo now offers their certificates on USB tokens:
https://www.leaderssl.com/suppliers/comodo/products/code_signing
https://www.leaderssl.com/suppliers/comodo/products/code_signing_ev
As an alternative, we now offer certificates from Certum:
https://www.leaderssl.com/suppliers/certum/products/code_signing_ev
https://www.leaderssl.com/suppliers/certum/products/code_signing
These are referred to as 'in the Cloud.'
You will need to use a special desktop application and sign via signtool.