Windows 10: Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root

Discus and support Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root in Windows 10 Software and Apps to solve the problem; Re this notice.Does this mean that everyone's PC must install the G2 protocol? Or is it for Windows servers only?How does this work for people OUTSIDE... Discussion in 'Windows 10 Software and Apps' started by Ian Mosley, May 10, 2022.

  1. Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root


    Re this notice.Does this mean that everyone's PC must install the G2 protocol? Or is it for Windows servers only?How does this work for people OUTSIDE the US accessing US services / servers and for Servers situated outside the US but sometimes serving US customers?

    :)
     
    Ian Mosley, May 10, 2022
    #1
  2. Tenforo Active Member

    Microsoft updates Trusted Root Certificate Program


    Source: Microsoft updates Trusted Root Certificate Program to reinforce trust in the Internet | Microsoft Malware Protection Center
     
    Tenforo, May 10, 2022
    #2
  3. Jan Fabry Win User
    Trust root or leaf certificate in 802.1x setup?

    I am setting up 802.1x via wired or wireless (WPA2 Enterprise) connections in our office, backed by a OneLogin RADIUS server. The certificate is not self-signed, so it's not clear to me whether it's safe to import it into the Trusted Root CA store, but that seems to be the only way to enable certificate checking.

    The certificate chain looks like this:

    • *.us.onelogin.com
    • RapidSSL SHA256 CA - G3
    • GeoTrust Global CA (already in the Windows Trusted Root CA store)

    The leaf and intermediate certificates are passed by the RADIUS server (verified using eapol_test).

    If I only enable the GeoTrust Global CA in the Protected EAP settings window, I still get a warning in Windows 10, as if no certificate checking was enabled ("Continue connecting? If you expect to find in this location, go ahead and connect. Otherwise, it may be a different network with the same name."). The warning does not show if I import the OneLogin certificate in the Trusted Root CA store and enable it in the EAP settings. The "Connect to these servers" field is set to radius.us.onelogin.com, so a MitM attack doesn't seem possible with just the actual GeoTrust root certificate enabled?

    Is this expected behaviour? This (unrelated) Lync support article says that the Trusted Root CA store should only store self-signed certificates (which makes sense), and could cause issues otherwise. Also, in this answer to a similar question, I see "Some clients might be convinced to trust [the leaf certificate] directly, but not all of them permit such direct trust, and it would mean trouble when that certificate expires."
     
    Jan Fabry, May 10, 2022
    #3
  4. grawity Win User

    Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root

    Accept self-signed certificate system-wide without installing as root CA

    If the server is under your control:

    1. Create an actual root CA (e.g. with easy-rsa or Xca or Windows Server CA role).
    2. Replace the self-signed server certificate with one issued by your custom CA.
    3. Make sure the certificate you just issued is actually marked as a "leaf" / "end-entity" certificate. Look for the "X.509v3 Basic Constraints" extension – it must be present and say "CA: FALSE".
    4. Install the custom CA's root certificate into your computer.
    5. Safely store the CA private key so that it's only accessible whenever you need to issue a new cert.

    As the server's certificate contains "Basic Constraints: CA: FALSE", it will not be able to issue new certificates using just its own key.

    (The reason you need the CA to be separate is because directly installing the server's self-signed certificate into the "Trusted CA" folder may cause the system to ignore Basic Constraints – after all, it's installed as an authority. Separation avoids this problem, because you can safeguard the root CA keys.)

    As a bonus feature, you won't need to re-trust the server certificate when it expires or when its name changes – just use the same root CA to issue a new cert.
     
    grawity, May 10, 2022
    #4
Thema:

Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root

Loading...
  1. Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root - Similar Threads - Removal Federal Common

  2. Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...

    in Windows 10 Gaming
    Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...: Error enrolling certificates from our Enterprise Root CA - Some Servers and Some Certificates onlyThe generic error is:Certificate enrollment for Local system failed to enroll for a DomainControllerAuthentication certificate with request ID N/A from BRRJ1-SRV0024.qgog.ad\CA...
  3. Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...

    in Windows 10 Software and Apps
    Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...: Error enrolling certificates from our Enterprise Root CA - Some Servers and Some Certificates onlyThe generic error is:Certificate enrollment for Local system failed to enroll for a DomainControllerAuthentication certificate with request ID N/A from BRRJ1-SRV0024.qgog.ad\CA...
  4. Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...

    in Windows 10 Customization
    Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...: Error enrolling certificates from our Enterprise Root CA - Some Servers and Some Certificates onlyThe generic error is:Certificate enrollment for Local system failed to enroll for a DomainControllerAuthentication certificate with request ID N/A from BRRJ1-SRV0024.qgog.ad\CA...
  5. Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root

    in Windows 10 Gaming
    Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root: Re this notice.Does this mean that everyone's PC must install the G2 protocol? Or is it for Windows servers only?How does this work for people OUTSIDE the US accessing US services / servers and for Servers situated outside the US but sometimes serving US customers?...
  6. A certificate chain processed, but terminated in a root certificate which is not trusted by...

    in Windows 10 Gaming
    A certificate chain processed, but terminated in a root certificate which is not trusted by...: Hi,I have found same Microsoft files but with different hashes have different reputations and there are some problems with signature verfication like below figure event though the signer is Microsoft Corporation. what is the reason for this issue? A certificate chain...
  7. A certificate chain processed, but terminated in a root certificate which is not trusted by...

    in Windows 10 Software and Apps
    A certificate chain processed, but terminated in a root certificate which is not trusted by...: Hi,I have found same Microsoft files but with different hashes have different reputations and there are some problems with signature verfication like below figure event though the signer is Microsoft Corporation. what is the reason for this issue? A certificate chain...
  8. Group Policy Lockdown: Install Root Certificate

    in AntiVirus, Firewalls and System Security
    Group Policy Lockdown: Install Root Certificate: Hello,I am looking to implement a mitigation recommendation from MITRE outlined on the following page:https://attack.mitre.org/techniques/T1553/004/The recommendation is to prevent users from installing their own root certificate with non-admin privileges through a change in...
  9. Windows 10 - Various Trusted Root Certifications Expired

    in Windows 10 Customization
    Windows 10 - Various Trusted Root Certifications Expired: Recently less than a month ago, I had purchased a new Windows 10 Home edition workstation from IBUYPOWER. After getting this system dialed in I have found multiple Trusted Root Certifications that were expired. I then verified our Windows 10 Tablet from 2016 Surface Pro 4...
  10. Microsoft updates Trusted Root Certificate Program

    in Windows 10 News
    Microsoft updates Trusted Root Certificate Program: At Microsoft, we are continuously working to deliver on our commitment to the security of our customers and their ecosystems. A core component of our strategy to inform Windows users about the safety of the websites, apps and software they’re accessing online is built into...