# Code signing certificates

**URL:** <https://community.letsencrypt.org/t/code-signing-certificates/815>\
**Category:** Feature Requests\
**Created:** [September 9, 2015, 4:10pm UTC](https://community.letsencrypt.org/t/code-signing-certificates/815 "2015-09-09T16:10:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![PPT001](https://avatars.discourse-cdn.com/v4/letter/p/dbc845/32.png) [@PPT001](https://community.letsencrypt.org/u/PPT001)\
**Post date:** [September 9, 2015, 4:10pm UTC](https://community.letsencrypt.org/t/code-signing-certificates/815/1 "2015-09-09T16:10:20Z")

</div>

Hi,

Will it be possible to request , code (java, MS…) signing certificates

thx  
patrik

---

<div class="post-metadata">

**Author:** ![Jason](https://avatars.discourse-cdn.com/v4/letter/j/dc4da7/32.png) [@Jason](https://community.letsencrypt.org/u/Jason)\
**Post date:** [September 9, 2015, 4:33pm UTC](https://community.letsencrypt.org/t/code-signing-certificates/815/2 "2015-09-09T16:33:29Z")

</div>

No, this is only for SSL web server.

---

<div class="post-metadata">

**Author:** ![eva2000](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eva2000/32/289_2.png) [@eva2000](https://community.letsencrypt.org/u/eva2000)\
**Post date:** [September 9, 2015, 4:51pm UTC](https://community.letsencrypt.org/t/code-signing-certificates/815/3 "2015-09-09T16:51:58Z")

</div>

> [@Do you support Code Signing](https://community.letsencrypt.org/t/do-you-support-code-signing/370):
>
> D…

---

<div class="post-metadata">

**Author:** ![kelunik](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/kelunik/32/359_2.png) [@kelunik](https://community.letsencrypt.org/u/kelunik)\
**Post date:** [September 13, 2015, 8:49pm UTC](https://community.letsencrypt.org/t/code-signing-certificates/815/4 "2015-09-13T20:49:43Z")

</div>

Actually, it’s not only for web servers, but any TLS usage, so also POP or SMTP servers.

---

<div class="post-metadata">

**Author:** ![My1](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/my1/32/1013_2.png) [@My1](https://community.letsencrypt.org/u/My1)\
**Post date:** [November 23, 2015, 8:56am UTC](https://community.letsencrypt.org/t/code-signing-certificates/815/5 "2015-11-23T08:56:14Z")

</div>

well code signing requires a different level of trust and is usual bound to the natural or business entity and not just the domain, and therefore an automatic check isnt possible, meaning you wont get a code-signing so fast.

---

<div class="post-metadata">

**Author:** ![weinert](https://avatars.discourse-cdn.com/v4/letter/w/8e7dd6/32.png) [@weinert](https://community.letsencrypt.org/u/weinert)\
**Post date:** [December 14, 2018, 12:59pm UTC](https://community.letsencrypt.org/t/code-signing-certificates/815/6 "2018-12-14T12:59:37Z")

</div>

For signing Java certifying domain ownership might be sufficient in many cases.  
If the first non-empty package starts with de.frame4j, e.g., the author should own the domain [frame4j.de](http://frame4j.de) use it for distributing the software and would mention that in the jar’s manifest as Implementation-URL, Codebase and Caller-Allowable-Codebase.

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [December 14, 2018, 4:43pm UTC](https://community.letsencrypt.org/t/code-signing-certificates/815/7 "2018-12-14T16:43:59Z")

</div>


