Microsoft Prepares Windows Code Signing for the Quantum Era
Microsoft is updating Windows code signing with new certificates, stronger cryptographic algorithms, and a future move toward post-quantum cryptography.
The company detailed the changes in KB5125813, warning that applications and IT processes that rely on hardcoded certificate or algorithm details could run into compatibility problems.
Windows Production PCA 2011 Expires in October 2026
One of the first major changes involves the Microsoft Windows Production PCA 2011 certificate.
The certificate expires on October 19, 2026, and Microsoft has already started replacing it with a newer PCA.
Most Windows software should continue working normally. However, applications or internal tools that explicitly check the old certificate authority name, certificate hash, digital fingerprint, or another fixed identifier could reject newly signed software.
That means some systems could incorrectly flag legitimate Microsoft-signed software simply because the certificate chain has changed.
Microsoft Is Moving to Stronger Signing Algorithms
Microsoft also plans to strengthen Windows Production signing later in 2026.
The company expects to introduce stronger cryptographic configurations, including RSA-3072 and SHA-384.
Developers should avoid building software that assumes Windows will always use a specific signing algorithm or certificate configuration.
Microsoft expects certificate rotations and cryptographic changes to continue as security requirements evolve, making fixed assumptions increasingly risky.
Post-Quantum Windows Signing Is Planned for 2027
The bigger change arrives in 2027, when Microsoft plans to move Windows Production signing toward post-quantum cryptography by default.
PQC aims to protect systems against future quantum computers that could potentially break several cryptographic algorithms in widespread use today.
Microsoft says it will account for compatibility with older Windows platforms and legacy systems during the transition.
The company has already outlined a broader quantum-safe security roadmap as it prepares its products and infrastructure for post-quantum security.
Some Apps and IT Processes Could Break
The biggest compatibility risk comes from applications that validate code signatures using hardcoded information.
Problems may affect systems that rely on fixed algorithm names, Certificate Authority names, certificate hashes, digital fingerprints, or other certificate and signing identifiers.
Those checks may fail even when Windows itself considers the software correctly signed.
Microsoft recommends relying on Windows trust mechanisms rather than manually validating specific certificate details.
What Developers and IT Admins Should Do
Organizations should review any applications, deployment tools, security systems, or internal processes that perform code-signing validation.
Microsoft recommends that developers and administrators:
- Use approved Windows trust APIs instead of hardcoded certificate data.
- Keep applications algorithm-agnostic wherever possible.
- Test software against upcoming certificate and signing changes.
- Review private trust stores for dependencies on certificates Microsoft may replace.
- Prepare software for future post-quantum cryptography requirements.
These changes matter most for organizations that maintain custom software, internal validation systems, or security tools that perform their own certificate checks.
Microsoft’s Windows Code-Signing Timeline
Microsoft has outlined several stages for the transition. It is replacing Windows Production PCA 2011 before the certificate expires on October 19, 2026. Later in 2026, Windows Production signing will move to stronger cryptographic configurations, including RSA-3072 and SHA-384.
In 2027, Microsoft plans to move Windows Production signing toward post-quantum cryptography by default. The company will also continue rotating certificates and updating signing algorithms as security requirements change.
Microsoft is making several other security and platform changes at the same time. The company recently warned Edge users that it is removing MDAG and WIP, while administrators also need to prepare for Microsoft retiring Entra ID CSS properties.
Via Neowin
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages