July 2020 Deployment Notice - Microsoft Trusted Root Program
On Tuesday, July 28th, 2020, Microsoft will release a planned update to the Microsoft Trusted Root Certificate Program.
This release will add the following roots (CA \ Root Certificate \ SHA-1 Thumbprint):
- Asseco Data Systems S.A. \ Certum EC-384 CA \ F33E783CACDFF4A2CCAC67556956D7E5163CE1ED
- Asseco Data Systems S.A. \ Certum Trusted Root CA \ C88344C018AE9FCCF187B78F22D1C5D74584BAE5
This release will add the EV Code Signing OID to the following roots:
- Amazon \ Amazon Root CA 4 \ F6108407D6F8BB67980CC2E244C2EBAE1CEF63BE
- Amazon \ Amazon Services Root Certificate Authority -- G2 \ 925A8F8D2C6D04E0665F596AFF22D863E8256F3F
- Amazon \ Amazon Root CA 2 \ 5A8CEF45D7A69859767A8C8B4496B578CF474B1A
- E-Tugra \ E-Tugra Certification Authority \ 51C6E70849066EF392D45CA00D6DA3628FC35239
- Digicert \ DigiCert Assured ID Root G3 \ F517A24F9A48C6C9F8A200269FDC0F482CAB3089
- Digicert \ thawte Primary Root CA - G3 \ F18B538D1BE903B6A6F056435B171589CAF36BF2
- Digicert \ DigiCert Global Root G2 \ DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
- Digicert \ DigiCert Trusted Root G4 \ DDFB16CD4931C973A2037D3FC83A4D7D775D05E4
- Digicert \ DigiCert Baltimore Root \ D4DE20D05E66FC53FE1A50882C78DB2852CAE474
- Digicert \ DigiCert \ A8985D3A65E5E5C4B2D7D66D40C6DD2FB19C5436
- Digicert \ DigiCert Assured ID Root G2 \ A14B48D943EE0A0E40904F3CE0A4C09193515D3F
- Digicert \ DigiCert Global Root G3 \ 7E04DE896A3E666D00E687D33FFAD93BE83D349E
- Digicert \ DigiCert High Assurance EV Root CA \ 5FB7EE0633E259DBAD0C4C9AE6D38F1A61C7DC25
- Digicert \ VeriSign \ 4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5
- Digicert \ VeriSign Universal Root Certification Authority \ 3679CA35668772304D30A5FB873B0FA77BB70D54
- Digicert \ DigiCert Assured ID Root CA \ 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43
- Digicert \ GeoTrust Primary Certification Authority - G3 \ 039EEDB80BE7A03C6953893B20D2D9323A4C2AFD
- AC Camerfirma, S.A. CHAMBERS OF COMMERCE ROOT - 2016 \ 2DE16A5677BACA39E1D68C30DCB14ABE22A6179B
- Comodo \ Sectigo (CCA) \ EE869387FFFD8349AB5AD14322588789A457B012
- Comodo \ Sectigo (AAA) \ D1EB23A46D17D68FD92564C2F1F1601764D8E349
- Comodo \ Sectigo ECC \ D1CBCA5DB2D52A7F693B674DE5F05A1D0C957DF0
- Comodo \ Sectigo \ AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4
- Comodo \ Sectigo ECC \ 9F744E9F2B4DBAEC0F312C50B6563B8E2D93C311
- Comodo \ Sectigo \ 2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
- Comodo \ Sectigo (AddTrust) \ 02FAF3E291435468607857694DF5E45B68851868
- GlobalSign \ GlobalSign Root CA - R1 \ B1BC968BD4F49D622AA89A81F2150152A41D829C
- GlobalSign \ GlobalSign Root CA - R3 \ D69B561148F01C77C54578C10926DF5B856976AD
- GlobalSign \ GlobalSign ECC Root CA - R5 \ 1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA
- Entrust \ Entrust \ B31EB1B740E36C8402DADC37D44DF5D4674952F9
- Entrust \ Entrust.net \ 8CF427FD790C3AD166068DE81E57EFBB932272D4
- Entrust \ Entrust (2048) \ 503006091D97D4F5AE39F7CBE7927D7D652D3431
- Entrust \ Entrust Root Certification Authority - EC1 \ 20D80640DF9B25F512253A11EAF7598AEB14B547
- Entrust \ Entrust Root Certification Authority - G4 \ 14884E862637B026AF59625C4077EC3529BA9601
- Global Digital Cybersecurity Authority Co., Ltd. \ GDCA TrustAUTH R5 ROOT \ 0F36385B811A25C39B314E83CAE9346670CC74B4
Note
- Windows 10 allows us to stop trusting roots or EKU's using the "NotBefore" or "Disable" properties, both of which allow us to remove certain capabilities of the root certificate without complete removal. These features are not available on versions prior to Windows 10. Earlier versions of Windows will be unaffected by this change.
- The NotBefore and Disable dates are set for the first day of the release month. This means that all certificates issued after April 1st will be affected.
- The update package will be available for download and testing at: https://aka.ms/CTLDownload
- Signatures on the Certificate Trust Lists (CTLs) for the Microsoft Trusted Root Program changed from dual-signed (SHA-1/SHA-2) to SHA-2 only. No customer action required. For more information, please visit: https://support.microsoft.com/en-us/help/4472027/2019-sha-2-code-signing-support-requirement-for-windows-and-wsus