3 ms·
Placing a certificate in the Trusted Root Certification Authorities node – despite completely "owning" a machine – is ironically not enough for a certificate to
by ComputerGuru 3y ago
Placing a certificate in the Trusted Root Certification Authorities node – despite completely "owning" a machine – is ironically not enough for a certificate to be used for driver code signing as even those need to be cross-signed by Microsoft to be accepted for kernel-mode drivers. I'm not sure this explanation holds any water.
(When it does suffice, the approach has always been generate a CA certificate on the device itself and install that, generate a cert signed by that CA to sign the code/driver with, then nuke the CA's private keys so they can't be used to sign anything else again. There would be zero need to ever use a real CA here.)