Light

Episode #1060 Quiz

3-Day Certificates
Date: 2026-01-13 | Length: 2.5 hrs | Episode page at twit.tv

About this episode

This episode explains code signing certificate changes, focusing on Microsoft's Azure Trusted Signing issuing short-lived three-day certificates to limit misuse if compromised. These certificates are paired with trusted timestamping authorities, which provide an unspoofable signing time, ensuring signature validity beyond certificate expiration.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to Rick Strahl's blog post discussed in the episode, what is a primary reason that modern code signing certificates must be stored as non-exportable either on certified online authorities or hardware security modules?
Question 2: What pricing and usage model does Microsoft's Azure Trusted Signing service offer for code signing certificates as reported in the episode?
Question 3: How does a Timestamp Authority (TSA) ensure that code signed with a short-lived certificate remains trusted long after the certificate's expiration?
Question 4: What is a significant operational challenge that Rick Strahl highlights about setting up Microsoft's Azure Trusted Signing service?
Question 5: What is the main functional difference between the validation of TLS web server certificates and code signing certificates, as explained in the episode?
Cancel