A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
Public Trust Test profiles exist specifically for inner-loop development and testing, without consuming or exposing publicly trusted certificates. They allow validation of signing flows, tooling, and pipelines in conditions that resemble Public Trust, but the issued certificates are intentionally not publicly trusted and should not be trusted by consumers.
Using a full Public Trust profile for internal builds does not provide additional benefit for reputation building. Reputation for Windows features (for example Smart App Control and SmartScreen) is driven by how publicly distributed, user-facing binaries behave and are seen in the ecosystem, not by internal or non-distributed builds. Signing internal builds with Public Trust only:
- Consumes publicly trusted certificates for artifacts that are never meant to be shared.
- Increases exposure risk if internal artifacts leak.
- Does not materially accelerate reputation for the public app, because reputation is tied to real-world distribution and usage of the signed artifacts.
Therefore:
- Use Public Trust Test profiles for inner-loop dev/test signing where public trust is not required.
- Use Public Trust profiles for artifacts intended for public distribution so users get the expected Windows security and trust experience.
References: