Microsoft is updating Windows Production CA, IT admins and devs should take action ASAP

Microsoft has been actively refining its Windows certificate framework throughout the year, with significant updates to Secure Boot certificates and the recent expiration of certain Windows 11 Insider certificates. In its latest advisory, the company has highlighted the importance of a new certificate update that, if not addressed promptly, could disrupt various applications and IT processes.

Key Updates in Code Signing Infrastructure

According to guidance published in KB5125813, Microsoft is undertaking a comprehensive update of the code signing infrastructure within Windows. This initiative aims to phase out outdated certificates, modernize signing algorithms, and prepare for the future of post-quantum cryptography (PQC). A critical point to note is the impending expiration of the Windows Production Public Certificate Authority (PCA) 2011, set for October 19, 2026, which will be succeeded by a new PCA. Additionally, Microsoft plans to adopt more robust signing algorithms, such as RSA-3072 and SHA-384, later this year. As the landscape of PQC evolves, the company is committed to implementing a flexible architecture that accommodates rapid changes to ensure continued security.

Applications and IT processes that depend on hardcoded algorithm names, certificate authority identifiers, hashes, or other digital signatures may encounter failures once these updates are implemented. Such dependencies could invalidate a code signing that Microsoft deems valid, simply because the validation processes are tethered to outdated technologies or certificates that have been rotated out.

In light of these developments, Microsoft encourages IT administrators and application developers to take proactive measures. They should:

  • Review current software to ensure validation through approved Windows trust APIs.
  • Adopt an algorithm-agnostic approach to enhance compatibility.
  • Test the impact of certificate changes on existing applications.
  • Examine private trust stores for potential issues.

IT administrators should also remain vigilant regarding the forthcoming PQC changes to ensure that both existing and future software solutions are resilient and secure.

Here is a summary of the timeline provided by Microsoft:

  • Now: The Microsoft Windows Production PCA 2011 is set to expire on October 19, 2026, with preparations for a replacement already in progress.
  • Later in 2026: Transition to stronger configurations for Windows Production signing will commence.
  • 2027: Windows Production signing will default to PQC, taking into account legacy systems and down-level platforms.
  • Ongoing: Continuous certificate rotations and algorithm updates will be implemented as security and customer requirements evolve.

With the clock ticking, IT administrators and application developers are urged to assess their current infrastructure promptly to prevent any compatibility issues as these changes take effect.

Winsage
Microsoft is updating Windows Production CA, IT admins and devs should take action ASAP