Required Root CAs and CTLs

From: Lars Olaussen (Isolauss_at_hotmail.com)
Date: 11/20/03


Date: Thu, 20 Nov 2003 11:35:08 +0100

In the MS Knowledge Base Article 293781 there is a list of 'Trusted Root
Certificates That Are Required By Windows 2000'.

Would it be possible to just add these root CAs to a Certificate Trust
List made by the own PKI implementeted? Then all the root CAs shipped
with Windows could be removed, and only the own PKI and PKIs signed in
CTLs would be accepted at domain workstations.

The first goal would be to require all drivers, applications etc to be
digitally signed. Then require all PKIs issuing these certificates to be
approved by the own root CA; never again have to worry about rogue
drivers and applications being signed by untrusted 'Trusted Root
Certificate'.

Regards,
Lars Olaussen
Isolauss@hotmail.com



Relevant Pages

  • [NT] Windows File Protection Arbitrary Certificate Chain Vulnerability
    ... Beyond Security would like to welcome Tiscali World Online ... Windows File Protection will trust any digital signature whose certificate ... chain is rooted at any one of the Trusted Root Certification Authorities. ... chains but also as valid Root CA's for code signing certificates. ...
    (Securiteam)
  • Re: Required Root CAs and CTLs
    ... No, you cannot add those to a CTL, they must be left in their native form. ... > Would it be possible to just add these root CAs to a Certificate Trust ... > List made by the own PKI implementeted? ... Then require all PKIs issuing these certificates to be ...
    (microsoft.public.windows.server.security)
  • Re: Required Root CAs and CTLs
    ... This feature is available in Windows 2003 through cross certification. ... Windows 2003 domain group policy you have two choices for PKI ... > Would it be possible to just add these root CAs to a Certificate Trust ... Then require all PKIs issuing these certificates to be ...
    (microsoft.public.windows.server.security)
  • Re: why do X.509 certificates contain context-specific tags?
    ... checked, some of the root ... I personally encountered certificates with a subject DN where some of ... committee-based development which tries to tackle complexity by throwing ... This can be opposed to much simpler PKI ...
    (sci.crypt)
  • Re: Enterprise root CA not re-trusted after manually deleted
    ... published) autoenrollment queries AD for CA certs and installs them. ... CA certs in AD). ... deleted root certs can automatically return or need a manual repair. ... If root CA certificates are distributed using autonenrollment (meaning ...
    (microsoft.public.windows.server.security)