Windows 10: Root CA certificate automatically added to local machine without internet connection

Discus and support Root CA certificate automatically added to local machine without internet connection in AntiVirus, Firewalls and System Security to solve the problem; On a fresh installed Windows 10 in virtual environment, that is disconnected from the internet by disabling the virtual network adapter, new root CA... Discussion in 'AntiVirus, Firewalls and System Security' started by Zhi Xuan Lim, Dec 8, 2020.

  1. Root CA certificate automatically added to local machine without internet connection


    On a fresh installed Windows 10 in virtual environment, that is disconnected from the internet by disabling the virtual network adapter, new root CA certificate is automatically added to the local machine trusted root certificate authorities after viewing the digital signature of a PE file properties --> digital signatures --> choose one of the signatures and press "details".

    Could you explain how Windows is obtaining the new root CA certificate when the machine is offline? As I understand, it should not be possible to obtain the new root CA certificate as connection to Windows Update Web site is unavailable and PE file typically does not embed the root CA certificate.


    The question i am asking is similar to this https://answers.microsoft.com/en-us/windows/forum/windows_10-security-winpc/root-certificate-authority-automatically-added/b25e07e6-ea1d-4181-98de-e4bc2e1677b3 . However, the older thread is does not have a conclusive answer and is locked from further discussion. Hence, I am re-posting the question. Any help will be much appreciated.

    :)
     
    Zhi Xuan Lim, Dec 8, 2020
    #1
  2. yiggal Win User

    root certificate authority automatically added without internet connection

    Windows adds root certificate authority - why and how?

    • After a fresh installation of Windows 10 or Windows 2012 while the devices is not connected to the internet, the system comes with a few basic root certificate authorities. (See image 1)
    • After copying over the installation file for Wireshark (a network sniffer), viewing the file's digital signature details (properties --> digital signatures --> choose one of the signatures and press "details"). (see image 2)
    • The certificate is automatically added to the trusted root certificate authorities. (see image 3)
    This is an example of an instance of this behavior. I've seen several more files with different certificates that Windows treats this way.

    I am aware that starting Windows Vista, Microsoft Windows doesn't contain all of the trusted root certificates in order to improve performance but is it actually so? Are the hashes of these certificates stored somewhere in the registry? If so, what if they
    are revoked?

    I would love to understand this more so if anyone can explain or refer me to documentation that can explain this behavior it will be greatly appreciated.

    Thank you,



    Images

    Image 1 - Windows 10 Certificates after clean install (notice - 14 root certificates)


    Root CA certificate automatically added to local machine without internet connection 04730d62-d498-4642-8eae-ec422a56d0d9.jpg


    Image 2 - View Digital Signature Details


    Root CA certificate automatically added to local machine without internet connection 0f47434e-0221-4d67-af13-02cbd939447c.jpg


    Image 3 - Root certificate authorities after viewing the file's digital signature (notice - 15 root certificates)


    Root CA certificate automatically added to local machine without internet connection 6a27d87f-ef5c-499d-a82b-c266cfd05512.jpg
     
    yiggal, Dec 8, 2020
    #2
  3. Root Certificate Program updates on mobile?

    what version of Windows Mobile or Windows Phone supports automatic update of root certification authorities according to the Root Certificate Program members?

    If 6.5 does not support it, is anywhere a list of preinstalled root CAs?

    if 7.0 does not support it, is anywhere a list of preinstalled root CAs?

    thanks. ondrej.
     
    Ondrej Sevecek, Dec 8, 2020
    #3
  4. Schmenk Win User

    Root CA certificate automatically added to local machine without internet connection

    AddTrust External CA Root certificate

    Hi!



    I am having the following problem: my employer is using an new security certificate for WiFi (AddTrust External CA Root certificate). I was wondering whether somebody can tell me how to install this new certificate on my N97 mini. I have
    the AddTrustExternalCARoot.crt file, but how to install on my device?



    Any suggestions are welcome, many thanx in advance!



    best, John
     
    Schmenk, Dec 8, 2020
    #4
Thema:

Root CA certificate automatically added to local machine without internet connection

Loading...
  1. Root CA certificate automatically added to local machine without internet connection - Similar Threads - Root certificate automatically

  2. Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...

    in Windows 10 Gaming
    Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...: Error enrolling certificates from our Enterprise Root CA - Some Servers and Some Certificates onlyThe generic error is:Certificate enrollment for Local system failed to enroll for a DomainControllerAuthentication certificate with request ID N/A from BRRJ1-SRV0024.qgog.ad\CA...
  3. Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...

    in Windows 10 Software and Apps
    Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...: Error enrolling certificates from our Enterprise Root CA - Some Servers and Some Certificates onlyThe generic error is:Certificate enrollment for Local system failed to enroll for a DomainControllerAuthentication certificate with request ID N/A from BRRJ1-SRV0024.qgog.ad\CA...
  4. Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...

    in Windows 10 Customization
    Error enrolling certificates from our Enterprise Root CA - Some Servers and Some...: Error enrolling certificates from our Enterprise Root CA - Some Servers and Some Certificates onlyThe generic error is:Certificate enrollment for Local system failed to enroll for a DomainControllerAuthentication certificate with request ID N/A from BRRJ1-SRV0024.qgog.ad\CA...
  5. Enterprise root CA recommendation

    in Windows 10 Gaming
    Enterprise root CA recommendation: Hi guys,I am fairly new to PKI so have some basic question about enterprise two tier PKI .Let's say we have root server, which is not the member of domain and normally stay powered down until we need to renew intermediate CA certificate.Does Microsoft recommend root server as...
  6. Enterprise root CA recommendation

    in Windows 10 Software and Apps
    Enterprise root CA recommendation: Hi guys,I am fairly new to PKI so have some basic question about enterprise two tier PKI .Let's say we have root server, which is not the member of domain and normally stay powered down until we need to renew intermediate CA certificate.Does Microsoft recommend root server as...
  7. Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root

    in Windows 10 Gaming
    Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root: Re this notice.Does this mean that everyone's PC must install the G2 protocol? Or is it for Windows servers only?How does this work for people OUTSIDE the US accessing US services / servers and for Servers situated outside the US but sometimes serving US customers?...
  8. Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root

    in Windows 10 Software and Apps
    Removal of the U.S. Federal Common Policy CA certificate from the Microsoft trusted root: Re this notice.Does this mean that everyone's PC must install the G2 protocol? Or is it for Windows servers only?How does this work for people OUTSIDE the US accessing US services / servers and for Servers situated outside the US but sometimes serving US customers?...
  9. Can't disable Automatic Root Certificates Update

    in Windows 10 Network and Sharing
    Can't disable Automatic Root Certificates Update: I run a clean install of Windows 10 Pro 20H2 19043.844 and if I disable Windows Automatic Root Certificate Update via GPEdit.msc then my internet stops working and all attempts at domain resolution fail. If try to disable Automatic Root Certificate Update by blocking...
  10. Toxic Root-CA certificates of WoSign and StartCom are still active in Windows 10

    in AntiVirus, Firewalls and System Security
    Toxic Root-CA certificates of WoSign and StartCom are still active in Windows 10: The root-CA certificates of WoSign and StartCom should be removed by Microsoft in 2017 due to their notoriety i.e. issuing fake/backdating certificates etc.. I am using Windows 10 Education Version 2004; OS build 19041.804, and at `certmgr.msc` I just saw that their...

Users found this page by searching for:

  1. automatic root certificates update windows offline