← Microsoft Corporation cases
Bugzilla #1670337 Certificate Misissuance

Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services experienced a certificate mis-issuance incident where certificates were issued for a domain that did not have a valid top-level domain (TLD). The issue was identified after a partner notified Microsoft on October 8, 2020. Following the notification, Microsoft took immediate action, including revoking the mis-issued certificates and improving their domain validation processes. The root cause was linked to a domain that was mistakenly added to their system, which was not public. Microsoft has since implemented measures to prevent similar incidents in the future, including enhanced checks and automation in their domain validation process.

Model: gpt-4o-mini Generated: 2026-06-13 21:12 UTC Confidence: 0.90
Chronology
  1. Microsoft was notified by a partner about the mis-issued certificates.
  2. Microsoft created an internal incident and began managing the issue.
  3. The problematic domain was removed from the production system.
  4. Certificates issued to the domain were revoked.
  5. Microsoft confirmed the removal of the DNS Operator exception from their CPS.
Participants
John Mason Ryan Sleevi Paul Steinberg Andrew Gwa Michel Le Bihan
Similar Local Cases
#1644936 RESOLVED Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 70% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1674561 RESOLVED Certificate Misissuance Opened 2020-10-31 · Closed 2023-02-22 · 61% similar
Microsoft PKI Services: DV certificate issued with OV fields
#1706860 RESOLVED Certificate Misissuance Opened 2021-04-22 · Closed 2023-02-22 · 60% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSName is not FQDN, Preferred Name Syntax
#1706950 RESOLVED Certificate Misissuance Opened 2021-04-22 · Closed 2023-02-22 · 59% similar
PKIoverheid: KPN issued Invalid organizationalUnitName
#1676352 RESOLVED Certificate Misissuance Opened 2020-11-10 · Closed 2023-02-22 · 58% similar
Microsec: Certificate validity period greater than 398 days
#1695786 RESOLVED Certificate Misissuance Opened 2021-03-01 · Closed 2023-02-22 · 58% similar
SECOM: Unqualified domain name in SAN
#1710243 RESOLVED Certificate Misissuance Opened 2021-05-08 · Closed 2023-02-22 · 56% similar
Sectigo: Invalid stateOrProvinceName
#1665763 RESOLVED Certificate Misissuance Opened 2020-09-17 · Closed 2023-02-22 · 55% similar
Sectigo: Failure to revoke within 5 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action