Digitally Signing 7-Zip Self-Extracting Archives

7-Zip does not natively apply digital signatures when creating self-extracting (SFX) archive executables, nor does it include a built-in feature to manage code signing certificates. While the stock SFX modules distributed with 7-Zip carry a digital signature from the developer, the process of appending archive data to the executable invalidates that original signature. However, the resulting .exe file fully supports post-creation digital signing using standard third-party tools like Microsoft's SignTool, allowing administrators and developers to distribute verified, trusted packages.

The Limitation of Native 7-Zip SFX Creation

When you create an SFX archive using 7-Zip (either via the graphical interface or the command-line utility), the program takes a precompiled executable module (such as 7z.sfx or 7zCon.sfx) and appends the compressed archive payload directly to the end of the file.

Because digital signatures depend on cryptographic hashes that verify file integrity:

  • Signature Invalidation: Any original signature present on the base SFX module becomes invalid the moment 7-Zip appends the archive data. Windows will treat the resulting binary as unsigned or tampered with.
  • No Built-in Signing Mechanism: 7-Zip does not contain code to hook into the Windows Certificate Store or apply a private key during the archive creation process.

How to Digitally Sign a 7-Zip SFX Executable

Even though 7-Zip cannot sign the file directly, the resulting SFX executable structure is compatible with standard Windows Authenticode signing. You can sign the .exe file immediately after 7-Zip creates it.

Step 1: Create the SFX Archive

Generate the executable archive normally using 7-Zip:

7z a -sfx7z.sfx package.exe .\SourceFiles\*

Step 2: Apply a Digital Signature

Use Microsoft's official SignTool utility (included with the Windows SDK) to apply your standard or Extended Validation (EV) code signing certificate to the generated executable:

signtool sign /f "YourCertificate.pfx" /p "YourPassword" /fd SHA256 /tr "http://timestamp.digicert.com" /td SHA256 "package.exe"

If you are using a hardware token or an EV certificate stored in the Windows Certificate Store, run:

signtool sign /a /fd SHA256 /tr "http://timestamp.digicert.com" /td SHA256 "package.exe"

Compatibility and Integrity Considerations

  • Archive Functionality Remains Intact: Standard Authenticode signatures append the digital signature data directly into a dedicated attribute certificate table defined by the Portable Executable (PE) specification. 7-Zip’s SFX stub reads the archive payload offset from the PE header structure, meaning the addition of an Authenticode signature does not corrupt or interfere with the archive extraction process.
  • SmartScreen and Antivirus Trust: Signing the finalized SFX archive with a trusted certificate prevents Windows Defender SmartScreen warnings, confirms publisher identity, and lowers the likelihood of false-positive detections by antivirus software.
  • Timestamping: Always include a timestamp server parameter (/tr and /td SHA256) when signing the executable. This ensures the digital signature remains valid even after your code signing certificate expires.