Home / bulletins Microsoft Security Advisory (2661254): Update For Minimum Certificate Key Length - Version: 1.1
Posted on 15 August 2012
Revision Note: V1.1 (August 14, 2012): Executive Summary corrected to help clarify that after applying this update, customers need to use certificates with RSA keys greater than or equal to 1024 bits in length.
Summary: Microsoft is announcing the availability of an update to Windows that restricts the use of certificates with RSA keys less than 1024 bits in length. The private keys used in these certificates can be derived and could allow an attacker to duplicate the certificates and use them fraudulently to spoof content, perform phishing attacks, or perform man-in-the-middle attacks.