Microsoft DSRE PKI: Microsoft shares wildcard certificates among cloud instances
This case involves Microsoft sharing wildcard certificates among its cloud instances, which resulted in a security vulnerability where the private key could be extracted by users. The issue was initially reported by Matthias Gliwka, who discovered that multiple customer instances were using the same wildcard certificate and private key, leading to potential unauthorized access. Microsoft was informed and began investigating the issue. The certificates were eventually revoked, and the case was marked as resolved. Further actions regarding the certificates were discussed, including potential updates to OneCRL.
- Initial report of shared wildcard certificates leading to private key exposure.
- Microsoft confirmed revocation of the affected certificates.
- Hboeck representative — Reported a problem with Microsoft involving a certificate whose private key is essentially public.
- Microsoft Corporation — Microsoft is investigating this issue.
- Mozilla representative — Microsoft representatives informed that they are actively engaged on this issue.
- Mozilla representative — Closing as resolved fixed, per email from Microsoft.