← Microsoft Corporation cases
Bugzilla #1602999 Ca Certificate Compliance Incident Self Reported Incident

Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-disclosure by Microsoft regarding a loss of approximately nine and a half months of archived firewall syslog data from a retention store in its monitoring and retention platform. Microsoft stated the issue was discovered while reviewing enhancements to the platform, and that the problem was detected on September 12, 2019. Microsoft said the misconfiguration causing the log loss was corrected within a couple of hours the same day, and that continuous monitoring and alerting for the retention part of the platform was implemented on October 7, 2019. Microsoft reported that the certificates issued during the loss timeframe were test certificates that had since expired, and that there were no problem certificates to report. Microsoft also stated that the issue was caused by human error in setting incorrect parameters for archival of firewall logs, and that periodic evidence requests had been fulfilled from the monitoring part of the platform rather than the retention part. In response to questions, Microsoft listed multiple Microsoft CA certificates active during the time of the loss and stated it performed root cause analysis and remediation, including automated monitoring/alerting and a manual check process as part of internal periodic audits. The bug was marked RESOLVED with resolution FIXED, and a Fastly participant indicated remediation was complete.

Model: gpt-5.4-nano Generated: 2026-06-13 21:01 UTC Revised: 2026-06-16 19:11 UTC Confidence: 0.90 5 comments
Chronology
  1. Microsoft detected a misconfiguration that resulted in loss of archived firewall syslog data from the retention store.
  2. Microsoft corrected the retention-store misconfiguration within a couple of hours.
  3. Microsoft implemented continuous monitoring and alerting for the retention part of the monitoring and retention platform.
Thread Activity
  1. Microsoft Corporation — Microsoft reported the loss of archived firewall syslog data, described detection and remediation timelines, and stated there were no problem certificates to report.
  2. Fastly representative — Fastly asked which Microsoft CA certificates were affected, why reporting was delayed, and whether a root cause analysis and prevention steps were performed.
  3. Microsoft Corporation — Microsoft answered the questions by listing CA certificates active during the loss window, explaining the reporting delay, and describing root cause analysis and remediation (automated monitoring/alerting and a manual check process).
  4. Microsoft Corporation — Microsoft noted an unintentional formatting issue in the middle of the response.
  5. Fastly representative — Fastly stated it appeared all questions were answered and remediation was complete.
Participants
Microsoft Corporation Fastly representative
External References
Similar Local Cases
#1604124 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2019-12-16 · Closed 2023-02-22 · 97% similar
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work
#1700809 RESOLVED Self Reported Incident Incident Opened 2021-03-25 · Closed 2023-02-22 · 90% similar
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 89% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 89% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 89% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 89% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#1718991 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-07-02 · Closed 2024-05-09 · 89% similar
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
#1598390 RESOLVED Ca Certificate Compliance Opened 2019-11-21 · Closed 2024-05-09 · 87% similar
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action