{"id":75534,"date":"2017-08-08T06:00:39","date_gmt":"2017-08-08T13:00:39","guid":{"rendered":"https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/?p=75534"},"modified":"2023-05-15T23:06:17","modified_gmt":"2023-05-16T06:06:17","slug":"microsoft-to-remove-wosign-and-startcom-certificates-in-windows-10","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2017\/08\/08\/microsoft-to-remove-wosign-and-startcom-certificates-in-windows-10\/","title":{"rendered":"Microsoft to remove WoSign and StartCom certificates in Windows 10"},"content":{"rendered":"
Microsoft has concluded that the Chinese Certificate Authorities (CAs) WoSign and StartCom have failed to maintain the standards required by our Trusted Root Program. Observed unacceptable security practices include back-dating SHA-1 certificates, mis-issuances of certificates, accidental certificate revocation, duplicate certificate serial numbers, and multiple CAB Forum Baseline Requirements (BR) violations.<\/p>\n
Thus, Microsoft will begin the natural deprecation of WoSign and StartCom certificates by setting a \u201cNotBefore\u201d date of 26 September 2017. This means all existing certificates will continue to function until they self-expire. Windows 10 will not trust any new certificates from these CAs after September 2017.<\/p>\n
Microsoft values the global Certificate Authority community and only makes these decisions after careful consideration as to what is best for the security of our users.<\/p>\n
Questions, concerns, or insights on this story? Join discussions at the Microsoft community<\/a> and Windows Defender Security Intelligence<\/a>.<\/p>\n