Describes an update for Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. This update adds the public key or signature hash of known untrusted certificates to CTL.
More...
For Update Tuesday we’re releasing seven security bulletins – three Critical-class and four Important – addressing 26 unique CVEs to further improve the security postures of Microsoft Windows, Internet Explorer, Dynamics AX, Microsoft Lync, and the Microsoft .NET Framework. In...
Revision Note: V1.0 (June 3, 2012): Advisory published.
Summary: Microsoft is aware of active attacks using three unauthorized digital certificates derived by a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or...
Today, as a part of our continuing phased mitigation strategy recently discussed, we have initiated the additional hardening of Windows Update. We’ve also provided more information about the MD5 hash-collision attacks used by the Flame malware in the SRD blog. This information should help...
Hello,
At Microsoft, our commitment is to help ensure customer trust in their computing experience. That was the impetus for Trustworthy Computing, and central to that is the priority we place on taking the necessary actions to help protect our customers.
Yesterday, we issued Security Advisory...
Fixes an issue in which a 0x80090022 error occurs when you run auto-enrollment for computer certificates on a client computer that is running Windows 7 or Windows Server 2008 R2.
More...
Fixes an issue in which the PIN dialog box does not appear or you are presented with all the certificates in the store when you try to access a WebDAV server that requires certificate authentication. This issue occurs in Windows 7 or in Windows Server...
More...
Fixes an issue in which the auto-enrollment process for computer certificates fails when you set up an enterprise CA on a client computer that is running Windows 7 or Windows Server 2008 R2.
More...
Hello, i'm looking to see if i can get some help regarding an issue i've been stumped on. Until tonight, i have never come across a WPA2 - Enterprise network connection so bear with me.
I recently received a work laptop which came auto-configured with passwords to my companies networks across...
Hi everyone,
As a follow-up to Friday’s blog post, today we released Security Advisory 2641690 to notify customers that we revoked the trust of DigiCert Sdn.Bhd in an update that moves two Intermediate Certificate Authorities (CA) certificates to the Microsoft Untrusted Certificate Store...
Severity Rating: Important
Revision Note: V1.0 (November 8, 2011): Bulletin published.
Summary: This security update resolves a privately reported vulnerability in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service...
active directory
ad lds
adam
authentication
certificate
configuration
domain
elevation of privilege
important
ldap
microsoft
network security
patch
patch management
revocation
security
update
vulnerability
windows
Hi everyone,
This post is to notify customers that Microsoft will revoke trust in an Intermediate Certificate Authority, DigiCert Sdn. Bhd. (Digicert Malaysia) in an update to be released through Windows Update.
DigiCert Sdn. Bhd is a Malaysian subordinate CA under Entrust and Verizon (GTE...
Fixes an issue in which a certificate mapping rule does not work for a client certificate that has Unicode encoding attributes in IIS 7.5. This issue occurs on a computer that is running Windows Server 2008 R2 or Windows 7.
Link Removed
Fixes an issue in which a certificate that has multiple chains cannot be validated in Windows Server 2008 R2 or in Windows 7. This issue occurs when one chain has a revoked certificate.
Link Removed
Fixes an issue in which you receive an "ERROR_IPSEC_IKE_CERT_CHAIN_POLICY_MISMATCH" error message when you try to start an IPsec connection between two computers. This issue occurs in Windows 7 or in Windows Server 2008 R2
More...
This KB article describes the proxy detection mechanism that the Cryptography (Crypto) API uses to download a CRL from a CRL distribution point. It discusses the locations of the registry where proxy information is found.
Link Removed