Updating Trusted Root CA

Updating Trusted Root CA

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Updating Trusted Root CA Jim 05-06-2008
Posted by Jim on May 6, 2008, 4:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
If you are working on a "legacy" system on windows; where do you go to for
an update of the trusted root CA lists? If any have expired or have
gone...with the wind, should I delete or let an update program perform this
action? Are the Intermediate CA's being updated also? tia-maria



Posted by Paul Adare on May 7, 2008, 3:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Tue, 6 May 2008 16:31:18 -0400, Jim wrote:

> If you are working on a "legacy" system on windows; where do you go to for
> an update of the trusted root CA lists? If any have expired or have
> gone...with the wind, should I delete or let an update program perform this
> action? Are the Intermediate CA's being updated also? tia-maria

If the application in question does not use the normal Windows APIs for
certificate management then you'll need to check with the application
vendor for this kind of information.
If the application is written to conform to the relevant RFCs then
intermediate certificates should be retrieved from the AIA location in the
certificate(s) it is consuming.

--
Paul Adare
http://www.identit.ca
The value of a program is proportional to the weight of its output.

Posted by Jim on May 7, 2008, 10:19 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I was referring to the certificate store onboard the local system. Windows
update would have an option to update these Trusted and Intermediate CA's.
However if windows 98se or 2k etc. windows update is no longer supported...
for these OS. Some of these CA's are still valid thru 2020 and some have
expired. Others have gone out of biz. Although I have not had problem with
these CA's, I was wondering where one would update the CA list for this
store and is it necessary to police the list prior if ever. The only CA's
that I have ever deleted were outdated personal and other peoples.

> On Tue, 6 May 2008 16:31:18 -0400, Jim wrote:
>
> > If you are working on a "legacy" system on windows; where do you go to
for
> > an update of the trusted root CA lists? If any have expired or have
> > gone...with the wind, should I delete or let an update program perform
this
> > action? Are the Intermediate CA's being updated also? tia-maria
>
> If the application in question does not use the normal Windows APIs for
> certificate management then you'll need to check with the application
> vendor for this kind of information.
> If the application is written to conform to the relevant RFCs then
> intermediate certificates should be retrieved from the AIA location in the
> certificate(s) it is consuming.
>
> --
> Paul Adare
> http://www.identit.ca
> The value of a program is proportional to the weight of its output.



Posted by Paul Adare on May 7, 2008, 12:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Wed, 7 May 2008 10:19:25 -0400, Jim wrote:

> I was referring to the certificate store onboard the local system. Windows
> update would have an option to update these Trusted and Intermediate CA's.

Root CAs only. Windows Update does not update intermediate CAs.

> However if windows 98se or 2k etc. windows update is no longer supported...
> for these OS. Some of these CA's are still valid thru 2020 and some have
> expired. Others have gone out of biz. Although I have not had problem with
> these CA's, I was wondering where one would update the CA list for this
> store and is it necessary to police the list prior if ever. The only CA's
> that I have ever deleted were outdated personal and other peoples.

If you feel the need to then manually manage the list. There's really no
point.

--
Paul Adare
http://www.identit.ca
Profanity is the one language all programmers know best.

Similar ThreadsPosted
Clients no longer pick up the Root CA as a trusted root authority June 6, 2006, 6:59 pm
Trusting Certs from Non Trusted root March 23, 2007, 6:38 pm
shutting down a trusted CA and raising a new trusted CA July 14, 2005, 1:32 pm
updating problem December 23, 2006, 11:10 am
Convert Enterprise Root CA to Standalone Root CA and create new Subordinate CAs March 19, 2008, 1:45 am
windows defender updating April 27, 2006, 10:31 am
Updating Spybot problem February 21, 2008, 12:32 pm
W2K, Windows Defender definitions are not updating. August 1, 2006, 1:02 pm
Migrating from single enterprise root CA to different root CA May 11, 2007, 6:43 am
Updating Ad-Aware SE Personal i SpyBot S&D from command line? October 7, 2005, 4:26 am

The site map in XML format XML site map

Contact Us | Privacy Policy