← Microsoft Corporation cases
Bugzilla #1586847
Certificate Problem Report
Microsoft PKI Services: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services issued intermediate certificates after January 1, 2019, that did not comply with Mozilla's policy, specifically lacking the required Extended Key Usage (EKU) extensions. This issue was identified during a compliance check, leading to the creation of an incident report. Microsoft acknowledged the error, revoked the problematic certificates, and updated their processes to ensure compliance moving forward. The incident was resolved with no valid problematic certificates remaining.
Chronology
- Microsoft issued non-compliant intermediate certificates.
- Incident bug 1586847 created.
- Microsoft revoked the initial versions of the problematic CAs.
- Incident report submitted by Microsoft.
- All questions answered and remediation confirmed complete.
Participants
Ryan Sleevi
Jason Cooper
Wayne Thayer
External References
Similar Local Cases
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
Microsoft PKI Services: Underscore in SAN
Camerfirma: Invalid authorityKeyIdentifier, violating Mozilla Policy and RFC 5280
Buypass: Missing NCA identifier in cabfOrganizationIdentifier in PSD2 QWACs
Consorci AOC: Non-BR-Compliant Certificate Issuance
Amazon Trust Services: Test revoked certificates with invalid validity period