Hi Stefani Warren
What’s happening is that Identrust shifted their PKI hierarchy earlier this year, and the new root chain didn’t line up with what Windows was trusting out of the box. That’s why your EV code signing cert suddenly stopped working mid‑June. Microsoft is rolling out a trust store update to include the new Identrust chain, and once that lands, your EV certs should validate again without any manual tweaks. In the meantime, some teams have worked around it by manually importing the updated Identrust root/intermediate certs into their local trust store, but I know that’s not ideal
The official update is scheduled to hit through Windows Update, so you’ll see it propagate automatically once it’s published. Keep an eye on your update logs, and after patching, try a quick signtool verify to confirm the chain resolves correctly.