Support for urgent Trusted Root updates for Windows Root Certificate ...
This article describes an update that enables urgent updates for the Windows Root Certificate Programin Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 8, Windows RT, Windows Server 2012, Windows 7, and Windows Server 2008 R2. Before you apply this update, see more about this updateand check out the prerequisites in this article.
An update is available that enables administrators to update trusted ...
This software update introduces a new tool that administrators can use to view the set of trusted root certificates in the Microsoft Root Certificate Program. This tool is for administrators who manage the set of trusted root certificates for an enterprise environment.
An automatic updater of untrusted certificates is available for Windows ...
Describes an update for Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. This update adds the public key or signature hash of known untrusted certificates to CTL.
KB5022661—Windows support for the Trusted Signing (formerly Azure Code ...
By default, root certificates are installed automatically if the computer is connected to the Internet. If the "automatic root certificates update" setting is disabled or the computer is offline, you must install this root certificate into the certificate store of "Local Computer" under "Trusted Root Certification Authorities".
March 10, 2026—KB5078938 (OS Build 14393.8957) | Microsoft Support
Important:Secure Boot certificates used by most Windows devices have started expiring in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. For details and preparation steps, see Windows Secure Boot certificate ...
Windows Secure Boot certificate expiration and CA updates | Microsoft ...
These original certificates are nearing their expiration date, and your device is affected if it has any of the listed certificate versions. To continue running Windows and receiving regular updates for your Secure Boot configuration, you will need to update these certificates.
IT admin guide: Secure Boot certificate update status in the Windows ...
Microsoft's Secure Boot certificates, originally issued in 2011, are approaching expiration in 2026. Updated 2023 certificates are being delivered automatically through Windows Update to consumer devices and some business devices. The Windows Security app now shows whether devices have received these updates, their current status, and whether any action is needed.
支持 Windows 中 Windows 根证书计划的紧急受信任根更新 | Microsoft Support
讨论 Windows 8.1、Windows RT 8.1、Windows Server 2012 R2、Windows 8、Windows RT、Windows Server 2012、Windows 7 和 中的 Windows 根证书计划更新的更新Windows Server 2008 R2。
KB5003341: Issues you might encounter when SHA-1 Trusted Root ...
As described in Microsoft to use SHA-2 exclusively starting May 9, 2021, beginning May 9, 2021 at 4:00 PM Pacific Time, all major Microsoft processes and services—including TLS certificates, code signing and file hashing—will use the SHA-2 algorithm exclusively.
KB5014754: Certificate-based authentication changes on Windows domain ...
To protect your environment, complete the following steps for certificate-based authentication: Update all servers that run Active Directory Certificate Services and Windows domain controllers that service certificate-based authentication with the May 10, 202,2 update (see Compatibility mode).