Petri
Microsoft Transitions Windows Code Signing to Post-Quantum Cryptography
Article Content
Microsoft is updating its Windows code-signing infrastructure to replace the expiring Windows Production PCA 2011 certificate by October 19, 2026, and is preparing for post-quantum cryptography (PQC) adoption in 2027. This transition may cause compatibility issues for applications that hardcode certificate identities or rely on outdated cryptographic standards. Developers and IT teams are advised to review their software's certificate validation processes to ensure compatibility with the new signing algorithms, including RSA-3072 and SHA-384. Microsoft emphasizes that applications should not depend on specific certificate names or algorithms but should use approved APIs for validation. The changes aim to enhance security against potential threats posed by quantum computing. Organizations must engage with software vendors to confirm compliance with the new standards before the transition takes effect.
Key Points: • Microsoft is replacing the Windows Production PCA 2011 certificate by October 19, 2026. • Post-quantum cryptography will be introduced by default in 2027 for Windows code signing. • Applications hardcoding certificate details may face compatibility issues during the transition.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.