Code Signing Hooks
Code signing hooks let you run custom application(s) any time code signing would occur on any file that is part or product of your build. To access your code signing hooks:
- Press SHIFT+CTRL+F11.
- On the tab, in the group, click .
- On the tab, in the group, click .
Code Signing Hooks Node
This page lets you configure your code signing hooks. Code signing hooks do not trigger unless authenticode signing has been enabled.
Commands
Specify one command on each line of this field.
You may run as many custom applications as necessary for your code signing to succeed. Each command executes sequentially in the order provided. Should any of the commands specified in this field, your build will fail due to a code signing error.
Enclose paths to applications containing spaces within double quotes (").
Enclose application parameters containing spaces within double quotes as well ("), otherwise each space delineates a new application command line parameter.
If you use compiler variables in this field, most commonly to reference the project folder (#PROJDIR#) and the InstallAware toolchain folder (#IADIR#), they will be resolved to their literal values during a build process.
Example Workflow Using Azure Trusted Signing
As of this writing, you may complete the steps below to sign your binaries using .
Please note that you must already have an account with and have completed identity validation.
Getting ready
- Install the latest version of the from https://dotnet.microsoft.com/en-us/download/dotnet/8.0.
- Install the latest version of the from https://learn.microsoft.com/en-us/cpp/windows/latest-supported-vc-redist?view=msvc-170.
- Install the latest of the from https://aka.ms/installazurecliwindowsx64 (64-bit) or https://aka.ms/installazurecliwindows (32-bit). Installing non- versions of these command line tools from their main download page at https://learn.microsoft.com/en-us/cli/azure/install-azure-cli-windows may cause failures later in the process and is not recommended.
- Download the from https://www.nuget.org/packages/Microsoft.Trusted.Signing.Client using the link under the heading. Add a .zip file extension to the downloaded .nupkg file, and extract it using DiskZIP. This tutorial assumes you have extracted these files to the root of your c:\ drive using the right-click action on the downloaded archive.
- Copy the file signtool.exe from your InstallAware installation folder to the c:\microsoft.trusted.signing.client.1.0.60.nupkg folder created in the step above.
- Create your code signing file as described at https://learn.microsoft.com/en-us/azure/trusted-signing/how-to-signing-integrations#create-a-json-file and place it inside this same folder above with the file name file.json.
- Optionally, login to your account by sequentially executing the commands described in the steps below from the command line. While these steps are optional, they prevent failures that may occur later in the process, and are recommended.
Logging on
- Run az login --user <your email address> --password <your password>. If this command fails, logon interactively instead running az login.
- Run az login --tenant <your tenancy GUID>.
- Run az account set --subscription "<your subscription GUID>". Please be advised that the s in the two steps above are supposed to be different from one another.
Signing code
- In the dialog (SHIFT+CTRL+F11), select the node beneath the node, and check the box. You do not need to fill in (or clear) any of the other fields on this page, as they will be ignored whether they are populated or not.
- Select the node beneath the node, and type the command c:\microsoft.trusted.signing.client.1.0.60.nupkg\signtool.exe sign /v /fd SHA256 /tr "http://timestamp.acs.microsoft.com" /td SHA256 /dlib "c:\microsoft.trusted.signing.client.1.0.60.nupkg\bin\x64\Azure.CodeSigning.Dlib.dll" /dmdf "c:\microsoft.trusted.signing.client.1.0.60.nupkg\file.json" "%1" on a single line.
Your setups and code will now be signed using as an integral part of your build process, bestowing the benefit of instant trust on your packages.



