← Microsoft Corporation cases
Bugzilla #1598390 Certificate Problem Report

Microsoft PKI Services: Null Character Bug and Microsoft Root CAs

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft reported a null character issue in certificates issued by its PKI Services, stemming from a bug in Windows Server 2012 R2 Certificate Services. This issue was identified during x509lint tests, but Microsoft deemed it cosmetic, as it did not affect the functionality of the certificates. No updates were issued to address the bug, and Microsoft has since transitioned to newer server versions. They have committed to revoking affected certificates and improving their pre-issuance linting processes to prevent future occurrences.

Model: gpt-4o-mini Generated: 2026-06-13 20:19 UTC Confidence: 0.95
Chronology
  1. Private report sent to Microsoft regarding the null character issue.
  2. Bug 1598390 opened to document the issue.
  3. Reissued all affected root certificates with added linting steps.
  4. Revoked all previous issuing CAs that contained the null character bug.
Participants
Jason Cooper Julio Montano Ryan Sleevi Kathleen Wilson Wayne Thayer
Similar Local Cases
#1604124 RESOLVED Certificate Problem Report Opened 2019-12-16 · Closed 2023-02-22 · 75% similar
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work
#1586847 RESOLVED Certificate Problem Report Opened 2019-10-07 · Closed 2024-05-09 · 75% similar
Microsoft PKI Services: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1718991 RESOLVED Certificate Problem Report Opened 2021-07-02 · Closed 2024-05-09 · 69% similar
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
#1390988 RESOLVED Certificate Problem Report Opened 2017-08-16 · Closed 2023-02-22 · 65% similar
Consorci AOC: Non-BR-Compliant Certificate Issuance
#1705419 RESOLVED Certificate Problem Report Opened 2021-04-15 · Closed 2023-02-22 · 63% similar
Microsoft PKI Services: Underscore in SAN
#1605372 RESOLVED Certificate Problem Report Opened 2019-12-20 · Closed 2023-02-22 · 63% similar
GlobalSign: OCSP responders found to respond signed by the default CA when passed an invalid issuer in request
#1599571 RESOLVED Certificate Problem Report Opened 2019-11-26 · Closed 2023-02-22 · 63% similar
TrustCor: Non-revocation of CA certificates within 7 days
#1599503 RESOLVED Certificate Problem Report Opened 2019-11-26 · Closed 2024-06-30 · 62% similar
TrustCor: No mention of TLS-capable Intermediate CAs in WTBR audit reports

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action