Skip to content

Trusted Root Certificate Stores for Windows

The Certificate Library Item now supports granular control over where PKCS #1 certificates are installed on Windows devices.

This feature extends certificate management by allowing PKCS #1 certificates to be targeted to specific Windows certificate stores, including Trusted Root Certification Authorities, Trusted Publishers, OEM eSIM Certification Authorities, Trusted People, and Untrusted Certificates. Administrators can upload PKCS #1–formatted certificates and select the appropriate store based on trust and usage requirements.

Correct certificate placement is critical to certificate trust, authentication, signing and secure communications. Granular store selection reduces misconfiguration risk, supports advanced security scenarios, and aligns certificate deployment with Windows security expectations.

Windows certificate configuration showing selectable trusted root certificate stores

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.