Signing the rollout packages - Documentation for BMC Client Management 21.02
The certificate used for signing. It is picked up from the master certificates repository. You must add this certificate on the master server. If there is no certificate on the master, you will not see any option in this list. By default, this field is empty.
To add the certificate on the master:
1. Copy the certificate contents in bin/certs/other/myCert.crt.
2. Copy the unencrypted certificate key in bin/certs/other/myCert.key.
3. Restart the service.
The certificate appears in the console and the you can configure the rollout signing with this certificate.
- Use a code signing certificate purchased from a trusted authority such as Digicert.
- Generate a custom authority, patch all windows devices to add this authority as a trusted one for code signing (using a GP rule for example), generate a certificate issued by this authority, and use it for signing.