Microsoft PKI Services: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
This case involves Microsoft PKI Services' issuance of intermediate certificates that did not comply with Mozilla Policy requirements effective January 1, 2019. The issue was identified by the Microsoft team during a compliance check, revealing that the 'Microsoft TLS EV Issuing CA 02' lacked the required Extended Key Usage (EKU) extension. In response, Microsoft renewed the affected certificates and revoked the non-compliant versions. An incident report was submitted detailing the compliance failure and corrective actions taken, including updates to their CA ceremony processes to prevent future occurrences. The case has been resolved with all necessary actions completed.
- Microsoft issued non-compliant intermediate certificates.
- Microsoft revoked the initial versions of the non-compliant CAs.
- Community commenter — Discovered that Microsoft issued an intermediate that does not conform with Mozilla Policy.
- Microsoft Corporation — Confirmed that the CA was renewed to include the required EKUs.
- Microsoft Corporation — Attached the Incident Report for Bug 1586847.
- Community commenter — Requested more detailed explanations regarding the incident.
- Fastly representative — Noted that original versions of the CA certificates had not been disclosed in CCADB.
- Fastly representative — Confirmed that all questions have been answered and remediation is complete.