Choosing Your USB Token and CA
OneSigner signs with the certificate you bring — it works with any PKCS#11 USB token and any CA. That freedom raises the first real question of every deployment: which token, and which CA? Here is the practical answer.
Tokens that work
- SafeNet eToken 5110 — the token most CAs ship for code-signing and document-signing certificates. Fully supported, including unattended PIN entry.
- ePass2003 — common with national and Asian CAs for document signing; a frequent choice for invoice workflows.
- YubiKey 5 (PIV) — excellent for code signing; supports attestation and slots 9a/9c. OneSigner can select by YubiKey serial and PIV slot.
- Anything PKCS#11 / CNG-visible — if Windows can see the certificate and the vendor middleware exposes the key, OneSigner can sign with it.
Practical tips: use a powered USB hub for multi-token setups; label tokens physically; and check the token's PIN retry counter policy — OneSigner stops before a wrong stored PIN can lock a token.
Which CA — by what you sign
Documents (PDF)
- Legal validity at home: a certificate from your national accredited CA gives your signatures direct standing under your country's e-transaction law (ETA in Singapore, eIDAS in the EU, and equivalents elsewhere).
- The Adobe green tick worldwide: choose a CA on the Adobe Approved Trust List (AATL) — e.g. GlobalSign, SSL.com, Sectigo — so recipients see "Signature valid" with no extra setup.
- EU qualified signatures (QES): a qualified certificate from an EU trust-list provider on a qualified device — recognised in every member state.
Windows code
- An OV or EV code-signing certificate from a Microsoft-trusted CA (SSL.com, GlobalSign, Sectigo…). Since the CA/Browser Forum changes, these keys ship on hardware — which is exactly the deployment OneSigner is built for.
One box, many certificates
You do not have to choose one: plug in a national-CA token for local invoices, an AATL token for international contracts, and an EV token for releases — one signing profile per certificate routes each job to the right token automatically.
We are an authorized reseller for the major CAs — browse code-signing and document-signing certificates, many of which include a free OneSigner license.
Related: We resell certificates as well as build the software, which is a slightly awkward position to be in. Why we built OneSigner explains how that came about.