Coming Soon: GET:IT Endpoint Management 1-Day Conference on September 28th at 9:30 AM ET Coming Soon: GET:IT Endpoint Management 1-Day Conference on September 28th at 9:30 AM ET
Security|Windows 10

Microsoft to Remove Some Chinese Certificate Authorities from Windows 10

Microsoft to Shut Down MSN China
Image credit: Associated Press

Microsoft has announced today that the company will be removing certificate authorities from WoSign and StartCom from Windows 10. The company says that these providers have failed to maintain the standards required by the Trusted Root Program.

The listed offenses committed by these authorities include back-dating SHA-1 certificates, mis-issuances of certificates, accidental certificate revocation, duplicate certificate serial numbers, and multiple CAB Forum Baseline Requirements (BR) violations. To little surprise, Microsoft does not approve of any of these violations and as such, is removing their ability to issue new certificates and invalidating their old files.

Starting on September 26th, Microsoft will begin the process of removing support for these certificates. If your company is using a CA from one of these providers, you will need to update your certificates immediately.

In the blog post which you can view here, Microsoft notes that they value the CA community and only makes these decisions after careful consideration. Or in other words, these providers screwed up so badly and repeatedly that the company was forced to revoke their access after they failed, on multiple occasions, to fix their processes.

Sponsored Content

Say Goodbye to Traditional PC Lifecycle Management

Traditional IT tools, including Microsoft SCCM, Ghost Solution Suite, and KACE, often require considerable custom configurations by T3 technicians (an expensive and often elusive IT resource) to enable management of a hybrid onsite + remote workforce. In many cases, even with the best resources, organizations are finding that these on-premise tools simply cannot support remote endpoints consistently and reliably due to infrastructure limitations.

The Trusted Root program, starting with Vista, is updated on Windows automatically. Knowing this, the revoke process for removing these expired certificates will not require any interaction be the end user.

Related Topics:

BECOME A PETRI MEMBER:

Don't have a login but want to join the conversation? Sign up for a Petri Account

Register
Comments (0)

Leave a Reply

Brad Sams has more than a decade of writing and publishing experience under his belt including helping to establish new and seasoned publications From breaking news about upcoming Microsoft products to telling the story of how a billion dollar brand was birthed in his book, Beneath a Surface, Brad is a well-rounded journalist who has established himself as a trusted name in the industry.

Live on Tuesday, September 28th, at 9:30 AM ET!

GET-IT: EndPoint Management 1-Day Virtual Conference

The management of endpoints is complicated and the risks associated with having unsecured devices roaming outside the firewall are quickly becoming a targeted vector for malicious users. In this Petri one-day virtual conference, we will be diving deep into how you can improve the way you manage your endpoints and learn from industry experts and MVPs about best practices, available tools to streamline your operations, and what's coming soon with Windows 11.

RSVP Now!

Sponsored By

Live Webinar: Active Directory Security: What Needs Immediate Priority!Live on Tuesday, October 12th at 1 PM ET

Attacks on Active Directory are at an all-time high. Companies that are not taking heed are being punished, both monetarily and with loss of production.

In this webinar, you will learn:

  • How to prioritize vulnerability management
  • What attackers are leveraging to breach organizations
  • Where Active Directory security needs immediate attention
  • Overall strategy to secure your environment and keep it secured

Sponsored by: