Support Forum: Get Support for Patch My PC Products and Services

Microsoft Configuration Manager and Intune (Enterprises/Paid) => Knowledge Base Articles => Topic started by: Justin Chalfant (Patch My PC) on December 28, 2018, 01:34:06 PM

Title: PKI Certificate for Third-Party Update Code-Signing in SCCM
Post by: Justin Chalfant (Patch My PC) on December 28, 2018, 01:34:06 PM


Overview

  • In this video guide, we will cover how you can use a code-signing certificate from an Active Directly Certificate Services infrastructure or using a public certificate authority such as DigiCert for signing third-party software updates in Microsoft System Center Configuration Manager (SCCM). Using a trusted PKI based code-signing certificate can be an alternative to using a self-signed certificate.

Topics in Video

Helpful Resources:

Title: Re: PKI Certificate for Third-Party Update Code-Signing in SCCM
Post by: RaslDasl on October 17, 2019, 09:35:52 PM
What would be the reason to use a PKI cert rather than letting SCCM create and manage the cert?
Title: Re: PKI Certificate for Third-Party Update Code-Signing in SCCM
Post by: Justin Chalfant (Patch My PC) on October 18, 2019, 07:45:14 AM
PKI is generally considered a little more best-practice since certs are issues from a trusted CA and can be more easily revoked. Here are some resources that may be helpful

https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/self-signed-certificates-secure-so-why-ban/
https://en.wikipedia.org/wiki/Self-signed_certificate