Microsoft gives users a patch break, and time to prep for certificate slaying

06.09.2012

During its investigation into Flame, Microsoft decided to harden the Windows certificate infrastructure. The result was its decision to block access to certificates with keys shorter than 1,024 bits.

"I'd bet that they always wanted to do this," said Storm, "but historically, Microsoft wants to support all their customers, even those with much older systems that rely on shorter keys. Because of Flame, they had a good reason to make this move."

Next week's update, while light, was still interesting to Storms, who noted that Patch Tuesday will not fix any flaws in Internet Explorer (IE), making this the first month in the last four to omit the browser.

In July, Microsoft announced it was , and would ship patches when they were ready.

Microsoft will release the two updates at approximately 1 p.m. ET on Sept. 11.