how it works usually:
- When building, a checksum-hash of the bundled code is created. So, if the code changes, the hash changes.
- This checksum is then encrypted with a private key
- Resulting is a certificat, which contains the public key and organization/person who signed the code
- Then, usually, the operating system, e. g. Windows, checks the signature when starting the application.
Creating the private key on your own, thus, is very insecure. When the private key gets compromised on your machine, attackers could abuse your organizations identity.
Therefore, private keys are rather stored in Hardware Security Modules, but cloud providers make them more and more obsolete.
See: Hashing Encryption