Skip to content

March 2026 update#20

Open
kasirota wants to merge 5 commits intomainfrom
March-2026-Update
Open

March 2026 update#20
kasirota wants to merge 5 commits intomainfrom
March-2026-Update

Conversation

@kasirota
Copy link
Copy Markdown
Contributor

No description provided.

kasirota added 5 commits March 4, 2026 15:10
Clarify requirements for root certificates and their scopes.
Updated validity period for newly minted Root CAs to a maximum of 10 years, effective July 1, 2026.
Added clarification on Microsoft’s classification of suspect code and its relation to the Unified Security Operations criteria.
Added requirement for Certificate Authorities to disclose incident reports in Bugzilla and notify Microsoft.
- This EKU is used for signing documents within Office. It isn't required for other document signing uses.

**3.4.3** Effective for all root certificates submitted on or after July 1, 2026:
Effective for all root certificates submitted on or after July 1, 2026, root certificates MUST be limited in scope and dedicated to a clearly defined trust purpose.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Considering that the id-kp-clientAuth KeyPurposeId is allowed further below, please consider making the following change:

Suggested change
Effective for all root certificates submitted on or after July 1, 2026, root certificates MUST be limited in scope and dedicated to a clearly defined trust purpose.
Effective for all root certificates submitted on or after July 1, 2026, root certificates MUST be limited in scope and dedicated to clearly defined trust purposes.

**3.1.7.** Root Key Sizes must meet the requirements detailed in "Signature Requirements" below.

**3.1.8.** Newly minted Root CAs must be valid for a minimum of eight years, and a maximum of 25 years, from the date of submission.
**3.1.8.** Newly minted Root CAs must be valid for a maximum 10 years, from the date of submission, effective July 1, 2026.
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It seems this requirement limits the usage of cross-signing chains, leading to breakage on devices older than 10 years old. I'm just wondering if this is also an intended outcome?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants