code signing

Winsage
September 27, 2026
Windows 11 requires drivers to be digitally signed, a policy aimed at enhancing security by preventing unauthorized code from executing at the kernel level. This requirement, which began with Windows Vista and became mandatory with Windows 10, version 1607, has tightened over the years, especially with the introduction of UEFI Secure Boot and TPM in Windows 11. While this enforcement protects against malware and supports anti-cheat systems in gaming, it limits user autonomy and imposes significant challenges for developers, particularly those working on smaller projects. In contrast, Linux allows users more freedom to modify their systems, though this flexibility can compromise security.
Winsage
August 24, 2026
Microsoft has issued an advisory to IT teams and software developers regarding significant changes in Windows code signing due to the expiration of the Windows Production PCA 2011 certificate in October 2026. The transition will involve stronger cryptographic algorithms, including RSA-3072 and SHA-384, which may cause compatibility issues for applications that rely on hardcoded certificate checks or outdated cryptographic standards. Microsoft plans to implement post-quantum cryptography by default for Windows code signing in 2027. IT administrators are encouraged to assess their software environments, confirm vendor compliance with supported trust-validation mechanisms, and ensure applications are tested against the new certificate hierarchy and signing algorithms. Organizations with private trust stores must establish processes for recognizing and deploying legitimate Microsoft certificate updates.
Search