Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
Microsoft PKI Services reported a null character issue in certificates caused by a bug in Windows Server 2012 R2 Certificate Services. The problem was discovered during x509lint tests, and Microsoft proactively disclosed it to Mozilla. Although the issue was deemed cosmetic and did not impact certificate functionality, Microsoft ceased issuing new certificates with the problem and committed to using updated server versions. They have since reissued the affected root certificates and implemented additional linting steps in their CA processes to prevent future occurrences. The bug has been resolved, and the reissued certificates are now compliant.
- Microsoft PKI Services opened an incident report regarding the null character issue.
- Microsoft revoked the affected certificates.
- Microsoft confirmed the completion of remediation steps.
- Microsoft Corporation — Microsoft reported a null character issue in certificates and outlined their findings.
- Mozilla representative — Kathleen emphasized the CA's responsibility to review all certificates in their hierarchies.
- Microsoft Corporation — Julio confirmed that updates regarding the new replacement roots were added to relevant bugs.