{"id":15793,"date":"2022-09-21T17:07:19","date_gmt":"2022-09-21T21:07:19","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=15793"},"modified":"2023-05-24T10:48:46","modified_gmt":"2023-05-24T14:48:46","slug":"what-is-a-digital-signature","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-is-a-digital-signature\/","title":{"rendered":"What Is a Digital Signature &#038; How Does It Help Your Organization?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-digital-signatures-are-at-the-heart-of-secure-online-communications-they-not-only-validate-that-you-re-really-you-i-e-not-an-imposter-but-digital-signatures-also-offer-assurance-that-the-data-you-re-providing-is-authentic-and-hasn-t-been-altered\">Digital signatures are at the heart of secure online communications. They not only validate that you\u2019re really you (i.e., not an imposter), but digital signatures also offer assurance that the data you\u2019re providing is authentic and hasn\u2019t been altered<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Think back to the last time you downloaded software from your favorite website. Were you able to download and install the software without triggering any unknown publisher warning messages? This likely means that the publisher essentially stamped their application with a digital signature before releasing it. What this communicates is that the software publisher:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cares about the security and integrity of their products, and<\/li>\n\n\n\n<li>Aims to provide users\u2019 operating systems and browsers with a way to differentiate their legitimate products from counterfeits.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">But what if you received unnerving warning messages telling you that the software can\u2019t be trusted or that Windows couldn\u2019t verify the publisher? This indicates that the publisher didn\u2019t apply a valid digital signature to their product. And not digitally signing your software is a big red flag from a security standpoint.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But what is a digital signature in terms of security? It\u2019s time to explore what a digital signature is and why using this type of verification method is crucial to your organization\u2019s defenses and reputation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-a-digital-signature-a-look-at-this-type-of-electronic-signature\">What Is a Digital Signature? A Look at This Type of Electronic Signature<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A digital signature, also called a <a href=\"https:\/\/www.thesslstore.com\/blog\/public-key-signature\/\">public key signature<\/a>, is a digital identifier that you can apply to files, email communications, websites, and other digital assets to prove their authenticity. It\u2019s a <a href=\"https:\/\/www.digicert.com\/support\/resources\/faq\/signature-trust\/what-is-the-difference-between-an-electronic-signature-and-digital-signature\">special type of electronic signature<\/a> that uses cryptography to show that your data is legitimate and hasn\u2019t been messed with. (All digital signatures are electronic signatures, but not all electronic signatures are digital ones \u2014 it\u2019s like how all types of ice cream are desserts but not all desserts are ice cream.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before the internet, people had to be in the same physical location to verify one another\u2019s identities and exchange secure communications. Now, you can use a digital signature to verify that you\u2019re really you and that the file or site you created is authentic without having to meet the other party face to face. For example, I could share a digitally signed file with a friend in Australia and they\u2019d be able to verify that I created it without actually being here next to me to observe my actions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-pki-is-what-makes-digital-signatures-possible\">PKI Is What Makes Digital Signatures Possible<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Digital signatures rely on <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-pki-a-crash-course-on-public-key-infrastructure-pki\/\">public key infrastructure<\/a> (PKI) \u2014 a system that uses two separate but related keys to secure data via encryption \u2014 and digital certificates. PKI is the foundation of security on the internet; it\u2019s all about providing a way to remotely authenticate parties and prove that the integrity of their data hasn\u2019t been compromised so the parties can communicate securely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Are digital signatures 100% foolproof? Of course not \u2014 no technology is. In this case, their effectiveness depends on the strength of the cryptographic algorithms used and your ability to secure your digital certificates\u2019 private keys. (If you don\u2019t secure your keys and they fall into the wrong hands, then bad guys can use them to sign counterfeit software and raise all kinds of hell.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But while digital signatures aren\u2019t perfect, they\u2019re a great solution in an age when virtually instantaneous remote communications are the norm.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-do-digital-signatures-do-it-s-all-about-creating-and-fostering-trust\">What Do Digital Signatures Do? It\u2019s All About Creating and Fostering Trust<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In a nutshell, digital signatures facilitate both of the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Authentication<\/strong> \u2014 This is all about showing that the digital asset in question is legitimate and came from you. It helps users know that you\u2019re not some shyster cybercriminal who created something malicious while impersonating a legitimate person or company.<\/li>\n\n\n\n<li><strong>Non-Repudiation<\/strong> \u2014 Basically, this means that you can show that you, and <em>only you<\/em>, signed something. This way, no one (including you) can come back later and say that it was signed by someone else. &nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A digital signature irrefutably ties you or your organization\u2019s digital identity to your digital certificate and key. A digital certificate, such as an <a href=\"https:\/\/www.thesslstore.com\/products\/ssl.aspx\">SSL\/TLS certificate<\/a>, is a data file that contains information about you and\/or your company and the entity (i.e., a publicly trusted certificate authority [CA]) that issued the certificate to you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Why does it matter who issued the certificate? Every publicly trusted digital certificate is issued by a third-party CA (think DigiCert, Sectigo, etc.). This is an entity that has to meet strict industry standards in order to have the authority to issue certificates that are trusted by browsers and operating systems. When a CA issues a certificate to you or your company, they use their good name and reputation to vouch for you and help you establish trust.&nbsp;<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n<h3 class=\"wp-block-heading\" id=\"h-using-a-digital-signature-is-like-hiring-a-notary-public\">Using a Digital Signature Is Like Hiring a Notary Public&#8230;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In some ways, applying a digital signature is similar to having a public notary. When signing important documents, you typically are required to have the notary witness the signing, verify your identity, and add their stamp to affirm the authenticity of your signature. This is because a notary public has been given the authority to sign and attest to the signing of documents in an official capacity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Likewise, a certificate authority acts similarly, essentially affirming that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You are who you claim to be, and<\/li>\n\n\n\n<li>You\u2019re truly the one who signed the item in question.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Much like how a notary needs to check your government-issued ID card to verify your identity, certificate authorities also validate you or your business by checking official government records and other trusted third-party resources. Once the CA verifies this information, they\u2019ll issue you a certificate from a trusted root.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-digital-signatures-rely-on-the-issuing-ca-s-chain-of-trust\">Digital Signatures Rely on the Issuing CA\u2019s Chain of Trust<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A trusted root, or root CA, is part of a critical element of public key cryptography called a \u201cchain of trust.\u201d Basically, this is a line of digital certificates, and each certificate contains information from the previous certificate that was used to sign it. In a traditional chain of trust:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The certificate you install on your website is issued and digitally signed by an intermediate CA.<\/li>\n\n\n\n<li>The certificate of the intermediate CA\u2019s certificate that issued the leaf certificate is issued and digitally signed by a root CA.<\/li>\n\n\n\n<li>The root CA\u2019s certificate is digitally signed by the root CA, which is stored offline in a highly secure location.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a quick look at the chain of trust for The SSL Store\u2019s SSL\/TLS certificate:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"472\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/thesslstore-digital-signature-SSL-TLS-chain-of-trust-example-1024x472.jpg\" alt=\"SSL\/TLS certificate chain of trust includes digital signatures\" class=\"wp-image-15159\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/thesslstore-digital-signature-SSL-TLS-chain-of-trust-example-1024x472.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/thesslstore-digital-signature-SSL-TLS-chain-of-trust-example-300x138.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/thesslstore-digital-signature-SSL-TLS-chain-of-trust-example-768x354.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/thesslstore-digital-signature-SSL-TLS-chain-of-trust-example.jpg 1099w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A series of screenshots showing TheSSLStore.com\u2019s website security certificate.<\/em><\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-digital-signatures-matter-to-your-organization\">Why Digital Signatures Matter to Your Organization<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When you add digital identity to your data, it&#8217;s shared with others. You\u2019re letting those parties know that your data is authentic and hasn\u2019t been messed with since you signed it. But that\u2019s not the only way that integrating digital signatures into your organization\u2019s cyber defenses can help you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adding digital signatures to your emails, documents, software, and digital communications also:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Mitigates phishing attacks and data exposure risks.<\/strong> If your employees know that they should expect only digitally signed emails from colleagues, this can prevent phishing scams from being successful. This, by extension, aids in mitigating the risk of your sensitive data and systems being exposed.<\/li>\n\n\n\n<li><strong>Increases your organization\u2019s digital security.<\/strong> Since some PKI certificates (such as SSL\/TLS, email signing certificates, and device certificates) also have the additional benefit of enabling encryption, it\u2019ll make your communications and data more secure. Which leads us to our next point\u2026<\/li>\n\n\n\n<li><strong>Aids your compliance efforts.<\/strong> Many regulations require the use of secure communications and connections to protect data in transit. Digital signatures improve the security of communications by helping you ensure that you\u2019re connecting to a legitimate party on the other end.<\/li>\n\n\n\n<li><strong>Helps you reduce costs. <\/strong>Whether it\u2019s preventing data breaches or avoiding non-compliance issues, using digital signatures can help you reduce or mitigate various costs, including breach mitigation-related costs and non-compliance fines and penalties.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-5-ways-you-re-probably-already-using-digital-signatures-within-your-organization\">5 Ways You\u2019re (Probably) Already Using Digital Signatures Within Your Organization<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You now know what a digital signature is and what it does. But where can you find these digital identifiers in use? Virtually everywhere, if you know what to look for! Digital signatures are commonly used to secure files and data for organizations in the following industries for organizations across virtually all sectors, including banking, government, healthcare, and sales.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are a few examples of common digital signature uses:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-create-secure-website-connections\">1.&nbsp;Create Secure Website Connections<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Look at the top of your browser at the web address bar. See the little security padlock icon in your web browser? This means that your website is secured via the HTTPS protocol.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"455\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/thesslstore-site-padlock-shadow-1024x455.png\" alt=\"The padlock in the browser's web address bar is circled. This icon communicates that the website is secure, meaning that it's using an encrypted connection that's established through a process that involves the use of digital signatures\" class=\"wp-image-15795\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/thesslstore-site-padlock-shadow-1024x455.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/thesslstore-site-padlock-shadow-300x133.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/thesslstore-site-padlock-shadow-768x342.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/thesslstore-site-padlock-shadow.png 1041w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Image caption: A screenshot of TheSSLStore.com\u2019s home page with the security padlock icon highlighted.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you initially connected to our website (TheSSLStore.com), our web server sent your browser an SSL\/TLS certificate. This certificate contains a wealth of verifiable identifying information about our domain and company. It also includes the digital signature of the publicly trusted certificate authority that issued the certificate to us. Your browser verifies this digital signature as part of the <a href=\"https:\/\/www.thesslstore.com\/blog\/explaining-ssl-handshake\/\">SSL\/TLS handshake<\/a> process that creates a secure, encrypted communication channel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To enable HTTPS on your website, purchase and <a href=\"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-install\/\">install an SSL\/TLS certificate<\/a> on your web server.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-authenticate-your-email-communications\">2.&nbsp;Authenticate Your Email Communications<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When you add a digital signature to your outbound emails, it offers your recipients assurance that the emails are legitimate and came from your email client. It\u2019ll look something like the image below (which was captured in Microsoft Outlook).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"809\" height=\"248\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/03\/email-signing-certificate-valid-digital-signature.png\" alt=\"An email screenshot that shows a ribbon and includes the message about how the email is digitally signed.\" class=\"wp-image-14349\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/03\/email-signing-certificate-valid-digital-signature.png 809w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/03\/email-signing-certificate-valid-digital-signature-300x92.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/03\/email-signing-certificate-valid-digital-signature-768x235.png 768w\" sizes=\"auto, (max-width: 809px) 100vw, 809px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot showing that one of the emails I\u2019d received was digitally signed using an email signing certificate.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If you want to prove your emails are authentic and haven\u2019t been tampered with, you can digitally sign your message and all attachments. Simply add an <a href=\"https:\/\/www.thesslstore.com\/products\/email-document-signing-certificates.aspx\">email signing certificate<\/a> to your email client (such as Outlook) and have at it. Once you do this and enable the digital signing feature, it makes the little verification ribbon appear in your outbound emails.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can also add an optional timestamp, which shows the precise date and time when your email was signed and verified. (This is always a good idea, as far as we\u2019re concerned!)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-offer-assurance-of-your-digital-files-authenticity\">3.&nbsp;Offer Assurance of Your Digital Files\u2019 Authenticity<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Creating fraudulent Office documents isn\u2019t rocket science \u2014 virtually anyone can do it. So, if you want to ensure that no one tampers with your PDF and Microsoft Office files, you can do so by attaching your digital signature. This is akin to giving your files an official stamp of authenticity, much like the notary stamp we mentioned earlier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a quick example of how it looks when you use a document signing certificate to sign your Adobe PDF files:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"790\" height=\"600\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/adobe-pdf-digital-signature.png\" alt=\"A screenshot showcasing how a digital signature looks for Adobe PDF files.\" class=\"wp-image-15163\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/adobe-pdf-digital-signature.png 790w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/adobe-pdf-digital-signature-300x228.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/adobe-pdf-digital-signature-768x583.png 768w\" sizes=\"auto, (max-width: 790px) 100vw, 790px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot of an example digital signature in a PDF file.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see, the digital signature provides the signer\u2019s name, date, and time of when the digital signature was applied. Furthermore, you can click on <strong>Certificate Details<\/strong> to view additional information, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Who issued the certificate,<\/li>\n\n\n\n<li>When it was issued, and<\/li>\n\n\n\n<li>Whether the certificate has been revoked.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Note that this digital signature is different from a basic typed signature (which can be easily faked). To start adding digital signatures to your files, you\u2019ll need to first get a <a href=\"https:\/\/www.thesslstore.com\/products\/email-document-signing-certificates.aspx\">document signing certificate<\/a>. After that, you\u2019ll need to install it in your device or client\u2019s trust store.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-4-ensure-the-authenticity-of-your-software-code-and-containers\">4.&nbsp;Ensure the Authenticity of Your Software, Code, and Containers<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The same concept applies to your code and executables. If you want to provide assurance that your software is legitimate and isn\u2019t counterfeit, digitally sign your executables using a standard code signing certificate. This will enable your verified organization information to display in the warning windows instead of the dreaded \u201cUnknown\u201d publisher message.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"961\" height=\"545\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/verified-vs-unverified-publisher-examples.jpg\" alt=\"Two comparison screenshots: The left one is yellow and has &quot;Unknown&quot; listed as the publisher. The one on the right is blue and lists &quot;Rapid Web Services LLC&quot; as the verified publisher.\" class=\"wp-image-15796\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/verified-vs-unverified-publisher-examples.jpg 961w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/verified-vs-unverified-publisher-examples-300x170.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/verified-vs-unverified-publisher-examples-768x436.jpg 768w\" sizes=\"auto, (max-width: 961px) 100vw, 961px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A side-by-side comparison that shows the difference between digitally signed software (right) and unsigned software. The one on the right shows that it comes from Rapid Web Services LLC, whereas the one of the left shows that the publisher is unknown (and, therefore, potentially dangerous).<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">But if you want to take your digital identity to another level, use an extended validation (EV) code signing certificate. Doing this ensures your software will automatically be trusted by browsers and operating systems and won\u2019t trigger the Microsoft Defender SmartScreen warnings like the one above.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-5-establish-digital-identities-for-your-network-s-connected-devices\">5.&nbsp;Establish Digital Identities for Your Network\u2019s Connected Devices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For all you IoT lovers out there, this one is for you. Digital signatures are a great way to add verifiable digital identity to your smart technologies. If you\u2019ve got remote monitoring devices deployed in the field, you need a way to verify that it\u2019s your legitimate devices that are connecting to your network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using digital certificates for these devices enables you to harness the power of digital signatures (and public key cryptography as a whole) to keep your network and device data as secure as possible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-digital-signatures-work\">How Digital Signatures Work<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We already wrote a comprehensive article on <a href=\"https:\/\/www.thesslstore.com\/blog\/how-do-digital-signatures-work-a-look-at-how-a-pki-signature-works\/\">how digital signatures work<\/a>, so we\u2019re not going to dive into all of that again here. Here\u2019s the quick overview of how using a digital signature works using an example of signing an executable:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A publisher applies a <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-hash-function-in-cryptography-a-beginners-guide\/\">hash function<\/a> (a type of cryptographic function) to their software application.<\/li>\n\n\n\n<li>They then take the resulting hash value (i.e., a fixed-length string of special characters) and use a code signing certificate\u2019s private key to encrypt it. This creates a digital signature.<\/li>\n\n\n\n<li>Next, they take the digitally signed file and upload it to their website, along with the corresponding public key.<\/li>\n\n\n\n<li>When a user downloads the software, they can then use that public key to decrypt the file.<\/li>\n\n\n\n<li>The user then can compare the provided hash value against one their system generates using provided values. (The hash value information will be provided in the file\u2019s <strong>Properties<\/strong> section under <strong>Digital Signatures<\/strong>, as shown in the screenshots below.)<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"443\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/winsdksetup-digitally-signed-software-example-1024x443.jpg\" alt=\"Three screenshots set side by side that walk you through where to find a signed executable's digital signature information.\" class=\"wp-image-15797\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/winsdksetup-digitally-signed-software-example-1024x443.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/winsdksetup-digitally-signed-software-example-300x130.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/winsdksetup-digitally-signed-software-example-768x332.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/winsdksetup-digitally-signed-software-example.jpg 1379w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A screenshot of the digital signature properties for a third-party executable file.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If the publisher-provided and generated hash values match, it means that the software is authentic and hasn\u2019t been tampered with since the publisher signed it. If they don\u2019t, it means that it\u2019s been altered somehow and shouldn\u2019t be trusted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-final-thoughts-on-digital-signatures-in-cyber-security\">Final Thoughts on Digital Signatures in Cyber Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As you\u2019ve learned, digital signatures have a place in virtually every organization. Digital signatures are all about establishing trust by providing users with a way to verify the authenticity of a product and its creator. Without them, you have no verifiable means to prove whether your software is legitimate or was created by an imposter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whether you\u2019re a mortgage broker, software publisher, or managed service provider (MSP), these cryptographic tools can make a world of difference in increasing the security of your products, services, and organization.<\/p>\n\n\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>Digital signatures are at the heart of secure online communications. They not only validate that you\u2019re really you (i.e., not an imposter), but digital signatures also offer assurance that the&#8230;<\/p>\n","protected":false},"author":17,"featured_media":15798,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16,10200],"tags":[8348],"class_list":["post-15793","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","category-monthly-digest","tag-digital-signatures","post-with-tags"],"views":11570,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2022\/09\/digital-signature-feature.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/15793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=15793"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/15793\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/15798"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=15793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=15793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=15793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}