4 ms·
The root certificates trusted by Windows are fetched from Microsoft's servers as needed. You can download all of them using the command: certutil -generate
by besselheim 10y ago
The root certificates trusted by Windows are fetched from Microsoft's servers as needed. You can download all of them using the command:
certutil -generateSSTFromWU roots.sst
Then if you open up roots.sst (it opens in certmgr.msc) and sort by Friendly Name, you should see the WoSign roots. You can then export these and import them into the Untrusted Certificates store if you wish to block WoSign as a trusted root.