Digitally Signing 7-Zip Self-Extracting Archives
7-Zip does not natively apply digital signatures when creating
self-extracting (SFX) archive executables, nor does it include a
built-in feature to manage code signing certificates. While the stock
SFX modules distributed with 7-Zip carry a digital signature from the
developer, the process of appending archive data to the executable
invalidates that original signature. However, the resulting
.exe file fully supports post-creation digital signing
using standard third-party tools like Microsoft's SignTool, allowing
administrators and developers to distribute verified, trusted
packages.
The Limitation of Native 7-Zip SFX Creation
When you create an SFX archive using 7-Zip (either via the graphical
interface or the command-line utility), the program takes a precompiled
executable module (such as 7z.sfx or
7zCon.sfx) and appends the compressed archive payload
directly to the end of the file.
Because digital signatures depend on cryptographic hashes that verify file integrity:
- Signature Invalidation: Any original signature present on the base SFX module becomes invalid the moment 7-Zip appends the archive data. Windows will treat the resulting binary as unsigned or tampered with.
- No Built-in Signing Mechanism: 7-Zip does not contain code to hook into the Windows Certificate Store or apply a private key during the archive creation process.
How to Digitally Sign a 7-Zip SFX Executable
Even though 7-Zip cannot sign the file directly, the resulting SFX
executable structure is compatible with standard Windows Authenticode
signing. You can sign the .exe file immediately after 7-Zip
creates it.
Step 1: Create the SFX Archive
Generate the executable archive normally using 7-Zip:
7z a -sfx7z.sfx package.exe .\SourceFiles\*Step 2: Apply a Digital Signature
Use Microsoft's official SignTool utility (included with
the Windows SDK) to apply your standard or Extended Validation (EV) code
signing certificate to the generated executable:
signtool sign /f "YourCertificate.pfx" /p "YourPassword" /fd SHA256 /tr "http://timestamp.digicert.com" /td SHA256 "package.exe"If you are using a hardware token or an EV certificate stored in the Windows Certificate Store, run:
signtool sign /a /fd SHA256 /tr "http://timestamp.digicert.com" /td SHA256 "package.exe"Compatibility and Integrity Considerations
- Archive Functionality Remains Intact: Standard Authenticode signatures append the digital signature data directly into a dedicated attribute certificate table defined by the Portable Executable (PE) specification. 7-Zip’s SFX stub reads the archive payload offset from the PE header structure, meaning the addition of an Authenticode signature does not corrupt or interfere with the archive extraction process.
- SmartScreen and Antivirus Trust: Signing the finalized SFX archive with a trusted certificate prevents Windows Defender SmartScreen warnings, confirms publisher identity, and lowers the likelihood of false-positive detections by antivirus software.
- Timestamping: Always include a timestamp server
parameter (
/trand/td SHA256) when signing the executable. This ensures the digital signature remains valid even after your code signing certificate expires.