The new Post.Trust root certificate for inclusion on the Microsoft Root Certificate Program has been released, and is available via Windows Update (Root Update package offered for download), and individually via Windows Update to Windows users visiting websites protected with a certificate chained from the Post.Trust root cert.
The Microsoft CTL standardizes the criteria for root certification authorities’ inclusion in the Windows XP operating system, Internet Explorer and future Microsoft product. When a user visits a secure Web site using HTTPS, reads a secure S/MIME e-mail, or downloads an ActiveX control that uses the Post.Trust root certificate, the Windows XP certificate chain verification software checks the appropriate Windows Update location and downloads the Post.Trust root certificate. This process is seamless to the user, as the user does not see any security dialog boxes or warnings. The download happens automatically, behind the scenes.
Post.Trust was first included in Microsofts CTL in April 2000. In order to successfully achieve acceptance into the Microsoft’s Root Certificate Program, Post.Trust was required to complete a WebTrust for Certification Authorities audit or provide an equivalent third-party attestation. While the WebTrust for Certification Authorities program is a highly recognised and respected audit process sponsored by The American Institute for Certified Public Accountant's (AICPA), it is primarily used by US based organisations. The equivalent third party verification used by Post.Trust and subsequently accepted by Microsoft was the ISO 27001 certification standard.
Under this process the Post.Trust Certification Authority (CA) was independently audited using established, recognized, and accepted principles and criteria as defined under the Information Security Management System Standards BS 7799:1999 to assess whether the Post.Trust CA adhered to a minimum standard for disclosures, policies, practices and monitoring procedures.
Post.Trust’s continued inclusion into the Microsoft Root Certificate Program is further recognition of the high standards that the company operates to. It ensures greater trust and ease-of-use for Post.Trust customers. Post.Trust will continue to build on this standard and its certification status to provide scalable, Public Key Infrastructures to enable businesses to communicate in a protected and trusted environment.
Details of the Microsoft Root Certificate Program members are available here.
Details on the Microsoft Root Certificate Program are available here.
The Root Certificate is available here.
It is also available via the Windows Catalog, search for Root Update, download the latest Root Certificate Update (released in May 2008), and install on any Windows PC (with Administrator privileges).