Site Search
Cart
SupportFree Trial
Sectigo
ShopGo to ShopEnterpriseGo to EnterprisePartnersGo to PartnersResourcesGo to ResourcesCompanyGo to Company
Contact Us
Sectigo
  • Support
  • Free Trial

To sign your code and documents, you pass the code and documents that you want to authenticate through a hashing algorithm and then use your private key to sign the hash, which results in a digital signature. You then build a signature block, which contains the digital signature and the code-signing certificate.

October 3, 2018

Tools like Microsoft's SignTool let you timestamp the signature block based on the current date and time that a timestamping service provider, such as Sectigo, provides. Finally, you bind the timestamped signature block to the original code or document, which you can now publish on your Web site for download.

As part of this process, you will need to know the URL of Sectigo's timestamping server: http://timestamp.sectigo.com

There are two popular timestamping protocols, which are both supported by our time-stamping server:

  • RFC 3161 timestamping is used by SignTool (using the "/tr" parameter) and other applications (such as jarsigner). Our timestamping server automatically selects the appropriate signature algorithm (RSA/SHA-256, RSA/SHA-384, or RSA/SHA-512) with which to sign each timestamp, based on the hash algorithm you specify (e.g., via SignTool's "/td" parameter).
  • Authenticode timestamping is used by older versions of SignTool (using the "/t" parameter) and SignCode. Due to this protocol's design, it is not possible for our timestamping server to automatically select the appropriate signature algorithm. We currently use RSA/SHA-384 by default. However, you may request a different signature algorithm by appending "?td=<hash_algorithm>" to the URL. e.g., http://timestamp.sectigo.com?td=sha256.

If you are timestamping several items with a script, please add a delay of 15 seconds or more between each one so that you're not hammering our servers.

If you require a timestamping service compliant with eIDAS, please use the following time-stamping server URL instead - http://timestamp.sectigo.com/qualified.

Resource Library

  • Blog Posts
  • Case Studies
  • Datasheets
  • In the News
  • Notifications
  • Podcasts
  • Press Releases
  • Product Videos
  • Tech Documents
  • Webinars
  • Whitepapers
Browse All
Sectigo
Sign up for Sectigo news and announcements
Subscribe Now
Connect
Email Sales
[email protected]
Email Channel Sales
[email protected]
Call (United States)
(888) 266 6361
Call (International)
+1 (914) 732 8446
Call (United Kingdom)
0204 519 2097
Call (France)
+33 3 66 72 95 95
Call (Spain)
+34 900 838 451
Call (Germany)
+49 800 1002328
Call (Italy)
+39 02 4792 1708
Call (Australia)
+61 3 9022 7226
twitterlinkedinyoutube
Products
  • TLS/SSL Certificates
  • Compare Certificates
  • Sectigo Certificate Manager
  • Signing Certificates
  • SiteLock Website Security
  • Website Backup & Recovery
  • HackerGuardian PCI Scanning
  • eIDAS Solutions
Partners
  • Partnering with Sectigo
  • Connect to Partner Portal
  • Sectigo University
  • WHMCS Plugin
Resources
  • In the News
  • Blog Posts
  • Knowledge Base
  • Press Releases
  • Technical Documents
  • Case Studies
  • Upcoming Events
  • Datasheets
  • Whitepapers
  • Notifications
  • Podcasts
  • Product Videos
  • Webinars
Company
  • About Sectigo
  • Leadership
  • Careers
  • Industry Awards
  • Contact Us
WebTrust for Network Security RequirementsWebTrust for Certification AuthoritiesWebTrust for CA - Extended ValidationWebTrust for CA - Extended Validation Code SigningWebTrust for CA - SSL Baseline with Network SecurityWebTrust for CA - Code SigningEU TrustEU Trust
© 2026 Sectigo Limited. All rights reserved.
  • Terms of Use
  • Privacy Policy
  • Vulnerability Disclosure Policy
  • CCPA Privacy Notice
  • Cookie Policy
  • Privacy Portal
  • Legal
Sectigo® and its associated logo are federally registered trademarks of Sectigo, and other trademarks used herein are owned and may be registered by their respective owners.