Updating ie certificates
Windows 10 has additional requirements to validate kernel-mode drivers, which are appropriately signed by Microsoft and a CA.
CAs who wish to become authorized for kernel mode code signing must complete the steps below.
To update the certificates for Internet access that are issued by Windows EBS, use the Update Certificates Wizard.
Certificates that are issued by Windows EBS typically expire after two years.
From what I've experienced, you still need to follow my guide [slides 15&16] and manually remove certificates the Cross Cert Removal Tools fails to remove. How can you (or your web server) trust the identity of someone over the network?
The wizard can update the following private Secure Sockets Layer (SSL) certificates: Updating your certificates briefly interrupts Internet connectivity and client access to Microsoft Exchange through Outlook Web Access.
Microsoft reserves the right to not include a CA in the Program for any reason or no reason at all, and such decisions are at Microsoft’s sole discretion.
All CAs in the Program must comply with these Continuing Program Requirements.
Certification Authorities ("CAs") that are current members of the Program are listed at
Starting with the release of Windows Vista, root certificates are updated on Windows automatically. The user does not see any security dialog boxes or warnings.
This infrastructure verifies that we are who we say we are.