$npx skillfedfor your agent

mscerts

Python package for providing Microsoft's CA Bundle.

With conditionsPyPI CryptographyReleased Jul 2026171.5K downloads / moMPL-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — mscerts-2026.7.1-py3-none-any.whl
v2026.7.1 · released 2026-07-01 · Python >=3.7

Yes, but only if you specifically need Microsoft's CA bundle. For general HTTPS and certificate validation, use certifi instead. Install mscerts only when your application explicitly requires Microsoft's Root Certificate Authorities—such as validating Windows signatures or in compliance-constrained environments. Be aware of the deprecation limitation documented in the package description.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Low installation friction with no runtime dependencies.
  • Active maintenance as of July 2026, though the project has modest visibility (5 stars).
  • The package is a straightforward certificate bundle mirror.

License · maintenance · safety

MPL-2.0 (copyleft) — Licensed under MPL-2.0 (copyleft). Users must comply with Mozilla Public License 2.0 terms if they modify or redistribute the package; for typical use (reading certificates), the license poses minimal practical constraint.

last release 2026-07-01 (44 days) · last repo commit 2026-07-01 · 5 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 171,531 downloads/mo, #10,362 on PyPI

Verify before relying

pip install mscerts

import mscerts
print(mscerts.where())
  • Whether the Microsoft CA deprecation warning (granular CA removal not reflected in bundle files) affects your specific use case or certificate validation chain.
  • Current size and update frequency of the Microsoft certificate bundle relative to your security requirements.
Same gist for agents: .md · .json

What it is and what it does

mscerts is a Python package that bundles Microsoft's Root Certificate Authorities from the Microsoft Trusted Root Program, similar to how certifi packages Mozilla's certificates. It provides a single function, `where()`, that returns the file path to a PEM-formatted certificate bundle, and can also be invoked from the command line. The package has no runtime dependencies and supports Python 3.7 through 3.14.

The package is explicitly positioned as a specialized alternative to certifi for scenarios where Microsoft's certificate store is specifically required—notably in projects like signify that validate Windows signatures. The maintainers warn that Microsoft's CA program allows granular deprecation of individual CAs that certificate bundle files cannot represent, meaning the bundle may inadvertently trust certificates no longer trusted in their intended context. For most general-purpose use, certifi is recommended instead.

Use it for

  • Validate Windows code signatures or Authenticode certificates in Python applications that need Microsoft's trust store.
  • Build tools or security software that must respect Microsoft's specific CA trust decisions rather than Mozilla's.
  • Environments where only Microsoft-trusted CAs are acceptable for compliance or policy reasons.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, but only if you specifically need Microsoft's CA bundle.

For general HTTPS and certificate validation, use certifi instead. Install mscerts only when your application explicitly requires Microsoft's Root Certificate Authorities—such as validating Windows signatures or in compliance-constrained environments. Be aware of the deprecation limitation documented in the package description.

Install

mscerts on PyPI

Before you install

Low installation friction with no runtime dependencies. Active maintenance as of July 2026, though the project has modest visibility (5 stars). The package is a straightforward certificate bundle mirror.

License in practice

Licensed under MPL-2.0 (copyleft). Users must comply with Mozilla Public License 2.0 terms if they modify or redistribute the package; for typical use (reading certificates), the license poses minimal practical constraint.

Quickstart

pip install mscerts

import mscerts
print(mscerts.where())

Verify before relying

  • Whether the Microsoft CA deprecation warning (granular CA removal not reflected in bundle files) affects your specific use case or certificate validation chain.
  • Current size and update frequency of the Microsoft certificate bundle relative to your security requirements.

Package facts

LicenseMPL-2.0 copyleft
Python supportSupports the current Python release >=3.7
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 44 days since the last release
Last repo commit
First released
Downloads171,531 / month, #10,362 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: Mozilla Public License 2.0 (MPL 2.0)Natural Language :: EnglishProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9

Evidence: mscerts-2026.7.1-py3-none-any.whl

Tags

Capabilities
microsoft root certificatesmicrosoft ca bundle pythonmscerts certificate authoritywindows trusted root certificatesmicrosoft certificate store access
Topics
certificate-authoritywindows-security

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “microsoft root certificates”

  • mscertsProvides access to Microsoft's Root Certificate Authorities bundle…
  • certifiCertifi provides Mozilla's curated collection of root SSL…
  • wassimaWassima provides access to your operating system's root certificate…

Give your agent the search over MCP, or paste the wish link into any chat.

More Cryptography packages

certifi Worth it
PyPI · Cryptography · released Jul 2026

Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.

MPL-2.0pure Python · 3.7+
1.9Bdownloads / mo
cryptography Worth it
PyPI · Cryptography · released Jul 2026

cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.

Apache-2.0 OR BSD-3-Clausecompiled wheel
1.5Bdownloads / mo
rsa Skip
PyPI · Cryptography · released Apr 2025

Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.

Apache-2.0pure Pythonabandoned
299.6Mdownloads / mo
pyOpenSSL With conditions
PyPI · Python Modules · released Aug 2026

pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.

Apache-2.0pure Python · 3.9+
294.2Mdownloads / mo
azure-identity Worth it
PyPI · Cryptography · released Mar 2026

Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.

license unclearpure Python · 3.9+
247.2Mdownloads / mo
PyNaCl Worth it
PyPI · Cryptography · released Jan 2026

PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.

Apache-2.0compiled wheel · 3.8+
246.6Mdownloads / mo

See also certipy · wassima · python-certifi-win32 · wincertstore · certifi-linux · truststore · secure-smtplib · qsAPI · fds.sdk.utils