Trusted Signing trust models (2024)

  • Article

This article explains the concept of trust models, the primary trust models that Trusted Signing provides, and how to use them in a wide variety of signing scenarios that Trusted Signing supports.

Trust models

A trust model defines the rules and mechanisms for validating digital signatures and ensuring the security of communications in a digital environment. Trust models define how trust is established and maintained within entities in a digital ecosystem.

For signature consumers like publicly trusted code signing for Microsoft Windows applications, trust models depend on signatures that have certificates from a Certification Authority (CA) that is part of the Microsoft Root Certificate Program. For this reason, Trusted Signing trust models are designed primarily to support Windows Authenticode signing and security features that use code signing on Windows (for example, Smart App Control and Windows Defender Application Control).

Trusted Signing provides two primary trust models to support a wide variety of signature consumption (validations):

  • Public Trust
  • Private Trust

Note

You aren't limited to applying the trust models that are used in the signing scenarios described in this article. Trusted Signing was designed to support Windows and Authenticode code signing and Application Control for Windows features. It broadly supports other signing and trust models beyond Windows.

Public Trust model

Public Trust is one of the two trust models that are provided in Trusted Signing and is the most commonly used model. The certificates in the Public Trust model are issued from the Microsoft Identity Verification Root Certificate Authority 2020 and comply with the Microsoft PKI Services Third-Party Certification Practice Statement (CPS). This root CA is included in a relying party's root certificate program, such as the Microsoft Root Certificate Program, for code signing and time stamping.

Public Trust resources in Trusted Signing are designed to support the following signing scenarios and security features:

We recommend that you use Public Trust to sign any artifact that you want to share publicly. The signer should be a validated legal organization or individual.

Note

Trusted Signing includes options for "test" certificate profiles under the Public Trust collection, but the certificates are not publicly trusted. The Public Trust Test certificate profiles are intended to be used for inner-loop dev/test signing and should not be trusted.

Private Trust model

Private Trust is the second trust model that's provided in Trusted Signing. It's for opt-in trust when signatures aren't broadly trusted across the ecosystem. The CA hierarchy that's used for Trusted Signing Private Trust resources isn't default-trusted in any root program and in Windows. Rather, it's designed to use in App Control for Business (formerly Windows Defender Application Control, WDAC) features, including:

For more information about how to configure and sign WDAC policies by using a Trusted Signing reference, see the Trusted Signing quickstart.

Next step

Trusted Signing trust models (2024)
Top Articles
TurboTax vs. H&R Block 2024 Review - NerdWallet
5 Things to Know About the Gemini Credit Card - NerdWallet
San Angelo, Texas: eine Oase für Kunstliebhaber
Skyward Houston County
Belle Meade Barbershop | Uncle Classic Barbershop | Nashville Barbers
St Petersburg Craigslist Pets
Aiken County government, school officials promote penny tax in North Augusta
Cvs Devoted Catalog
Mikayla Campinos Videos: A Deep Dive Into The Rising Star
Degreeworks Sbu
800-695-2780
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Account Suspended
How to Watch the Fifty Shades Trilogy and Rom-Coms
Unforeseen Drama: The Tower of Terror’s Mysterious Closure at Walt Disney World
Understanding Genetics
Dwc Qme Database
Craigslist Houses For Rent In Milan Tennessee
Hdmovie2 Sbs
Fleet Farm Brainerd Mn Hours
Myql Loan Login
Boxer Puppies For Sale In Amish Country Ohio
Sorrento Gourmet Pizza Goshen Photos
Victory for Belron® company Carglass® Germany and ATU as European Court of Justice defends a fair and level playing field in the automotive aftermarket
Copper Pint Chaska
Nearest Ups Ground Drop Off
Buhl Park Summer Concert Series 2023 Schedule
Tomb Of The Mask Unblocked Games World
Jazz Total Detox Reviews 2022
Datingscout Wantmatures
Publix Coral Way And 147
25Cc To Tbsp
Mrstryst
15 Downer Way, Crosswicks, NJ 08515 - MLS NJBL2072416 - Coldwell Banker
Ixlggusd
Timothy Kremchek Net Worth
Closest 24 Hour Walmart
Directions To 401 East Chestnut Street Louisville Kentucky
Studentvue Columbia Heights
Unifi Vlan Only Network
Express Employment Sign In
Appraisalport Com Dashboard Orders
Skyward Marshfield
Craigslist - Pets for Sale or Adoption in Hawley, PA
Callie Gullickson Eye Patches
Craigslist Odessa Midland Texas
Beds From Rent-A-Center
Tyrone Dave Chappelle Show Gif
Nkey rollover - Hitta bästa priset på Prisjakt
Syrie Funeral Home Obituary
Room For Easels And Canvas Crossword Clue
Latest Posts
Article information

Author: Roderick King

Last Updated:

Views: 5439

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Roderick King

Birthday: 1997-10-09

Address: 3782 Madge Knoll, East Dudley, MA 63913

Phone: +2521695290067

Job: Customer Sales Coordinator

Hobby: Gunsmithing, Embroidery, Parkour, Kitesurfing, Rock climbing, Sand art, Beekeeping

Introduction: My name is Roderick King, I am a cute, splendid, excited, perfect, gentle, funny, vivacious person who loves writing and wants to share my knowledge and understanding with you.