There are several well known methods of downloading certificate lists from Microsoft, including certutil -generateSSTfromWU c:\my_cert\
Doing that (or just downloading authrootstl.cab) gives me a collection of more than 400 root certificates.
Now, I know that none of my connected servers have that many certificates loaded: and I just looked at a Win10 workstation and it has ~90 trusted root certificates and around 70 third-party root certificates.
Why is it so? How many trusted root certificates does Windows start with, and why is there this much larger list?
0 Answers