We're preparing our first AppSource submission and finalizing code signing certificate purchase. A few questions for publishers who've been through this:
What CA/vendor did you use for code signing certs (Certum, DigiCert, Sectigo, others)? Any specific recommendations or issues to avoid?
Cloud-based signing (e.g., SimplySign) vs physical USB token — which do most publishers use for CI/CD integration (Azure DevOps)?
For publishers managing multiple extensions/publishers under one legal entity — do you use a single cert across all, or separate certs per publisher/product?
Any gotchas during AppSource validation specifically tied to code signing (cert type rejected, common file signing to the certificate errors, etc.)?
Appreciate any real-world experience shared. Thanks!

Report
All responses (
Answers (