← Microsoft Corporation cases
Bugzilla #1421820 Certificate Problem Report

Microsoft DSRE PKI: Microsoft shares wildcard certificates among cloud instances

RESOLVED FIXED Microsoft Corporation
AI Summary

A significant security issue was reported regarding Microsoft Dynamics 365, where multiple cloud instances were found to share the same wildcard certificate and private key. This flaw allows users to extract the private key, compromising its confidentiality. Despite initial denials from Microsoft, the issue was acknowledged, and they are currently investigating the matter. The certificate remains valid, and there are concerns about the implications of revocation on service compatibility. Microsoft has since revoked the problematic certificates and requested that further public disclosures be managed carefully.

Model: gpt-4o-mini Generated: 2026-06-13 17:40 UTC Confidence: 0.90
Chronology
  1. Initial report of the certificate issue by Hanno Boeck.
  2. Microsoft confirmed they are investigating the issue.
  3. Bug closed as resolved after Microsoft revoked the certificates.
Participants
Hanno Boeck Kathleen Wilson Gervase Markham Jeremy Rowley Gordon Bock
Similar Local Cases
#1427034 RESOLVED Certificate Problem Report Opened 2017-12-25 · Closed 2024-05-09 · 63% similar
DigiCert: localbattle.net certificate with private key in software / issued by Digicert
#1398269 RESOLVED Certificate Problem Report Opened 2017-09-08 · Closed 2023-02-22 · 61% similar
DigiCert: Non-BR-Compliant OCSP Responders
#1017157 RESOLVED Certificate Problem Report Opened 2014-05-28 · Closed 2023-02-22 · 60% similar
DigiCert: no subject alternative name in Siemens certs
#1433118 RESOLVED Certificate Problem Report Opened 2018-01-25 · Closed 2022-11-14 · 56% similar
Asseco DS / Certum: certificate issued by Certum with compromised private key not revoked (windows10.microdone.cn)
#1391087 RESOLVED Certificate Problem Report Opened 2017-08-16 · Closed 2023-02-22 · 55% similar
Visa: Non-BR-Compliant Certificate Issuance
#1353833 RESOLVED Certificate Problem Report Opened 2017-04-05 · Closed 2023-02-22 · 55% similar
GlobalSign: Incapsula issued a certificate for non-existing domain (testslsslfeb20.me)
#1304895 RESOLVED Certificate Problem Report Opened 2016-09-22 · Closed 2023-02-22 · 55% similar
DigiCert: TI Trust Technologies Global CA issued certificate with no subject alternative name extension
#1350615 RESOLVED Certificate Problem Report Opened 2017-03-25 · Closed 2022-11-14 · 55% similar
Camerfirma: Startcom are issuing by proxy using Camerfirma

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action