Windows File Protection will trust any digital signature whose certificate chain is rooted at any one of the Trusted Root Certification Authorities. Versions of Windows (and Internet Explorer) ship with various preconfigured Trusted Root Certification Authorities that are automatically trusted not just as potential Root CA's for SSL certificate chains but also as valid Root CA's for code signing certificates. Many Root CA's issue SSL certificates that have improper Key Usage and Enhanced Key Usage Object Identifiers (OIDs), and missing or invalid Basic Constraints, making many SSL certificates identical in function to more privileged certificates.
|