Trusted Root&Intermediate system certificates. Where check the list?

userwin

New member
Local time
2:01 PM
Messages
22
Trusted Root&Intermediate system certificates. Where check the list?

Hi.

We have many trusted root and intermediate certificates in the cert's store by default. Where to check these lists? To exclude "not default", "maybe potentially mаlware" root certs.
 

My Computer My Computer

At a glance

Windows 7 Pro 64bit
OS
Windows 7 Pro 64bit

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
Thanks, but I don't need "Move or copy an SSL certificate from a Windows server to another Windows server".
I want to check (to examine) the lists of all trusted root and intermediate certs that installed by default in the system. How can I do this? Is it possible? Is there any official web-page on microsoft.com with lists of all provided by default root certs and their description?
 

My Computer My Computer

At a glance

Windows 7 Pro 64bit
OS
Windows 7 Pro 64bit
None that I know of. That page shows where to go examine certs which is what I thought you wanted. If you see a suspicious cert try googling it but generally you shouldn't have to worry about certs unless you are a web admin. They are harmless and only used by the OS for encrypting information over the web and if you start removing them you could end up with website authentication issues. Due to the number of websites I doubt that Microsoft keeps any such lists.
 

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
Due to the number of websites I doubt that Microsoft keeps any such lists.
I speak about trusted root certs. For example I have only 56 now. That's why i think there is no technical problem to publicate such list.
 

My Computer My Computer

At a glance

Windows 7 Pro 64bit
OS
Windows 7 Pro 64bit
I'll explain in detail... We have preinstalled root certs in the system which came with OS and maybe some new through updates. But it's a security question, because any person who have local access to the computer and of course admin rights and even software can add a root cert to the store. And after that for example all web-server's certificates which signed with this root cert will be trusted! It's potentially dangerous and that's why i think microsoft must publicate officially this list on it's web-site .
 

My Computer My Computer

At a glance

Windows 7 Pro 64bit
OS
Windows 7 Pro 64bit

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt

My Computer My Computer

At a glance

Windows 8
Computer type
PC/Desktop
OS
Windows 8
I'm not sure how to answer your question or even what you are concerned with. Perhaps this will help though.

Windows and Windows Phone 8 SSL Root Certificate Program (Member CAs) - TechNet Articles - United States (English) - TechNet Wiki

Thanks, I also already found this and info about "Microsoft Root Certificate Program" and "How Update Root Certificates Communicates with Sites on the Internet"

Not a question but...The Update Root Certificates feature sends a request by HTTP? Certificate Support and Resulting Internet Communication in Windows Vista Why not by httpS? It's insecure!

Unless you are a webadmin I really don't see why you need to worry abput certs.
See above. I think clients must also worry about root certs :) if they worry about security.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 Pro 64bit
OS
Windows 7 Pro 64bit
I was mistaken above :) I found here CTL.
But how The Update Root Certificates feature sends a request by http o httpS is still a question!
 

My Computer My Computer

At a glance

Windows 7 Pro 64bit
OS
Windows 7 Pro 64bit
Back
Top