web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

No record found.

News and Announcements icon
Community site session details

Community site session details

Session Id :
Microsoft Dynamics 365 | Integration, Dataverse...
Answered

AppSource Code Signing — Industry Practice for ISV Publishers

(1) ShareShare
ReportReport
Posted on by 8

We're preparing our first AppSource submission and finalizing code signing certificate purchase. A few questions for publishers who've been through this:

  1. What CA/vendor did you use for code signing certs (Certum, DigiCert, Sectigo, others)? Any specific recommendations or issues to avoid?

  2. Cloud-based signing (e.g., SimplySign) vs physical USB token — which do most publishers use for CI/CD integration (Azure DevOps)?

  3. For publishers managing multiple extensions/publishers under one legal entity — do you use a single cert across all, or separate certs per publisher/product?

  4. Any gotchas during AppSource validation specifically tied to code signing (cert type rejected, common file signing to the certificate errors, etc.)?

Appreciate any real-world experience shared. Thanks!

Categories:
I have the same question (0)
  • Verified answer
    CU-1234529-002 Profile Picture
    283 on at

    Hi, based on our experience:

    We use DigiCert reliable and widely accepted for AppSource submissions, no issues with validation.

    We use a physical USB token works fine, though for CI/CD in Azure DevOps you'd need to handle the signing step manually or use a signing service since USB tokens don't integrate directly into pipelines.

    We use a single cert across extensions under the same legal entity, no issues so far.

    One thing to note beyond code signing  don't forget the CAR (Code Analysis Report) is also required for AppSource submission. Make sure your code passes CAR validation before submitting, as that's a common blocker.

    Hope this helps. Thanks

  • Suggested answer
    11manish Profile Picture
    1,389 Super User 2026 Season 2 on at

    Don't choose the CA based primarily on Certum vs DigiCert vs Sectigo. Choose a Microsoft-trusted CA, obtain a standard code-signing certificate, keep the private key in a properly protected HSM/cloud signing service, automate signing in Azure DevOps, reuse the certificate across your extensions where appropriate, and verify the final .app signature before AppSource submission.

  • Subra Profile Picture
    2,173 Super User 2026 Season 2 on at

    Hi @CU-1234529-002 

    Please use digicert certificate for the code signing.

    Thanks,
    Subra

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Women in Power Builds Momentum

Expanding mentorship, skilling, and AI innovation

Congratulations to the July Top 10 Community Leaders

These are the community rock stars!

Leaderboard > Microsoft Dynamics 365 | Integration, Dataverse, and general topics

#1
11manish Profile Picture

11manish 96 Super User 2026 Season 2

#2
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 56 Super User 2026 Season 2

#2
ParthPatel249 Profile Picture

ParthPatel249 56

Last 30 days Overall leaderboard

Product updates

Dynamics 365 release plans