PowerShell script signing requires: creating a code signing certificate using makecert or similar tools (A), enabling strong private key protection during certificate creation to prevent unauthorized use (B), and signing the script using Set-AuthenticodeSignature cmdlet (C). The public key is embedded in the certificate, not used separately for execution - the signature is verified automatically.