C#


CSHARP.INSEC.CERT.RS : Certificate Added to Root Store (C#)

Summary

Detected possible certificate added to root storage.

Properties

Class Name Certificate Added to Root Store (C#)
Significance security
Mnemonic CSHARP.INSEC.CERT.RS
Categories
CWE CWE:922 Insecure Storage of Sensitive Information
OWASP-2017 OWASP-2017:A2 Broken authentication
OWASP-2021 OWASP-2021:A7 Identification and authorization failures
Availability Available for C# only.
Enabling Checks for this warning class are disabled by default. To enable them, add the following WARNING_FILTER rule to the project configuration file.
WARNING_FILTER += allow class="Certificate Added to Root Store (C#)"

Resolution

Parameterize it in a configuration file.

Use safer protocols.

Relevant Configuration File Parameters

The following configuration file parameters affect checks for this warning class.