---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configure

# Configuring Code Signing {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Activate and configure Code Signing to verify the authenticity and integrity of your data.

Code Signing Enterprise requires an initial trust relationship between trusted and protected
instances that helps to prevent any unauthorized user with any authorization level from
accessing unapproved activities.

Refer to each topic to complete the configuration steps to establish the Circle of Trust with Code Signing Enterprise:

[Assign the Code Signing Administrator Role](https://servicenow-prod.fluidtopics.net/UvJWRFiZoD6UpHEgeQqEkg "Assign the Code Signing Administrator role to a user to access the Code Signing configuration experience.")
:   Assign the Code Signing Administrator role to a user to access the Code Signing configuration experience.

[Configure Code Signing Enterprise on your trusted instance](https://servicenow-prod.fluidtopics.net/w5le6F2Gscg6HqyopIqItg "Turn on and configure Code Signing on your trusted instance.")
:   Turn on Code Signing on your trusted instance.

[Upload your Code Signing configuration file to your protected instance](https://servicenow-prod.fluidtopics.net/o60PLWkAF~SWQwPD_kbvJA "Upload the configuration file generated on your trusted instance.")
:   Upload the configuration file generated on your trusted instance.

[Configure Code Signing Enterprise on your protected instance](https://servicenow-prod.fluidtopics.net/yskylTZibHsVPIFJNIHMlg "Turn on and configure Code Signing on your protected instance.")
:   Turn on and configure Code Signing on your protected instance.

[Turn on certificate validation](https://servicenow-prod.fluidtopics.net/zTvVCpcQuTnWcHlYVGsA4Q "Protect your instance with certificate based validation.")
:   Turn on certificate validation on your instance.

[Turn off Code Signing](https://servicenow-prod.fluidtopics.net/XwVmj7KnigSUroIfqy7B6Q "Disable code signing on your protected instance.")
:   Disable code signing on your protected instance.  
    Hinweis:  
    This optional step isn't part of the initial configuration for Code Signing
* **[Assign the Code Signing Administrator Role](https://servicenow-prod.fluidtopics.net/UvJWRFiZoD6UpHEgeQqEkg)**   
  Assign the Code Signing Administrator role to a user to access the Code Signing configuration experience.
* **[Configure Code Signing Enterprise on your trusted instance](https://servicenow-prod.fluidtopics.net/w5le6F2Gscg6HqyopIqItg)**   
  Turn on and configure Code Signing on your trusted instance.
* **[Upload your Code Signing configuration file to your protected instance](https://servicenow-prod.fluidtopics.net/o60PLWkAF~SWQwPD_kbvJA)**   
  Upload the configuration file generated on your trusted instance.
* **[Configure Code Signing Enterprise on your protected instance](https://servicenow-prod.fluidtopics.net/yskylTZibHsVPIFJNIHMlg)**   
  Turn on and configure Code Signing on your protected instance.
* **[Turn on certificate validation](https://servicenow-prod.fluidtopics.net/zTvVCpcQuTnWcHlYVGsA4Q)**   
  Protect your instance with certificate based validation.
* **[Quorum Controlled Certificate Revocation](https://servicenow-prod.fluidtopics.net/8NIDrK09lG3mn8Qi7pV0GQ)**   
  The quorum-controlled certificate revocation for Code Signing certificates provides a secure mechanism for a Code Signing admin to revoke Code Signing certificates. The revocation process involves submitting a request that requires approval from multiple stakeholders. This workflow helps to prevent accidental or unauthorized revocations.
* **[Turn off Code Signing](https://servicenow-prod.fluidtopics.net/XwVmj7KnigSUroIfqy7B6Q)**   
  Disable code signing on your protected instance.
* **[Load required key pairs and certificates for Code Signing](https://servicenow-prod.fluidtopics.net/pBPlA99ogAtjinKi66xQpg)**   
  Establish the relationship in a designated trusted instance using Code Signing. This first step loads two cryptographic keys into the trusted environment to establish a trusted source for updates to the production instance.
* **[Prepare Circle of Trust certificates](https://servicenow-prod.fluidtopics.net/ba6Os8vCBap75wcA4h9RjQ)**   
  Create an update set in the trusted environment to export the trusted certificate to the production environment.
* **[Import and install certificates for Circle of Trust](https://servicenow-prod.fluidtopics.net/SqrFc_BMAHJP6xVgpI38zA)**   
  Retrieve the update set in production to establish the trust relationship between the two instances. The certificates that have been created to represent trust in the trusted instance must be accepted into the protected instance.
* **[Turn on Code Signing](https://servicenow-prod.fluidtopics.net/MIqFrZIvFv5qJhYg_ygIWw)**   
  Turn on Code Signing in your trusted non-production instance to identify the trusted instances linking to your production instance.
* **[Create Code Signing key pairs and certificates](https://servicenow-prod.fluidtopics.net/xBYv3sdIb7gsqj711SlqJA)**   
  Create two key pairs to signed certificates to establish trust between your protected and trusted instances.
* **[Specify custom rules in ECC firewall](https://servicenow-prod.fluidtopics.net/7Ycl1F4Izrci5nLMF7dHcg)**   
  Configure the External Communication Channel (ECC) firewall in your MID Server by specifying the custom rules to selectively allow or reject the incoming message and override the Code Signing configuration.
* **[Change your Root of Trust configuration](https://servicenow-prod.fluidtopics.net/RT4t65HV6mkYfWQ7NoRwbg)**   
  Trust and use your own certificates instead of relying on ServiceNow build certificates (default) by changing to use your Root of Trust (ROT). ServiceNow components like script includes, business rules, etc., are signed at build time using a ServiceNow build time key (verification certificate is the ServiceNow build certificate).

