Share via

Applocker Rules and Root Certificate Dependency

EuroEager2008 171 Reputation points
2025-02-05T12:32:21.0466667+00:00

Using Applocker rules with Publisher conditions, which are based on digitally signed executable files.

The signatures are timestamped (countersigned) within the code signing certificate's validity period. When implemented correctly, everything functions well. However, a question arises regarding the dependency on root certificates, whether directly or indirectly linked (via intermediate certificates) to the signature.

Does Applocker require a valid trusted root certificate to allow or deny a signed file execution, or does the timestamp ensure the rule's outcome indefinitely? Specifically, does the expiration or revocation of the trusted root certificate impact Applocker, as long as the signature is timestamped as described?

An authoritative answer on this matter would be greatly appreciated.

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.