You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows证书存储中Trusted People与Trusted Devices的用途及适配咨询

Trusted People vs Trusted Devices in Windows Certificate Store: Use Cases for Your Certificate Pinning

Hey there! Let's break down these two certificate store folders and figure out which fits your certificate pinning needs perfectly.

Trusted People Folder

This store is designed explicitly for certificates of specific individuals, services, or entities that you (or your application) explicitly trust—regardless of whether their root CA is in the global Trusted Root Certification Authorities store (though in your case, you're already requiring a valid chain, so that's an extra layer of validation).

  • Key适用场景:
    • Storing leaf certificates for specific partners, services, or websites you want to trust directly (exactly your use case of third-party leaf certificates for pinning)
    • Scenarios where you don't want to trust an entire CA, just a single specific certificate issued by it
    • Client-side authentication where you need to trust a particular user's client certificate

For your certificate pinning workflow—validating the TLS chain and checking that the server's leaf certificate is in a trusted list—Trusted People is the ideal choice. It aligns perfectly with the intent of pinning specific, trusted entities rather than broad CA hierarchies.

Trusted Devices Folder

This store is purpose-built for certificates associated with hardware devices, not individual services or people. Think:

  • Certificates from smart cards, hardware security modules (HSMs), or USB security keys
  • Certificates for network devices like printers, IoT sensors, or servers acting as hardware endpoints
  • Device identity certificates used in machine-to-machine (M2M) authentication

This is not a fit for your scenario, since you're storing third-party personal/service leaf certificates, not hardware device identities. Using Trusted Devices here would be misaligned with the store's intended purpose and could cause confusion down the line (especially if other system tools or apps interact with this store expecting device certificates).

Recommendation for Your Desktop App

Go with the Trusted People store for your third-party leaf certificates. You can choose between the Current User (no admin rights needed, per-user scope) or Local Machine (admin rights required, system-wide scope) container depending on whether your app needs the pinned certificates to be available for all users or just the current one.

When implementing your pinning check, you'll want to:

  1. First validate the standard TLS certificate chain (ensuring the root is trusted)
  2. Then query the Trusted People store to verify that the server's presented leaf certificate exists in it

内容的提问来源于stack exchange,提问作者Gabor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:31:08