Microsoft PKI Services mis-issuance involving non-public DNS names and domain validation failures
Microsoft PKI Services reported that it had issued public TLS certificates for a domain that was not public and therefore failed the DNSNames must have a valid Top-Level Domain check. The issue was first reported to Microsoft by an external partner on 2020-10-08, after which Microsoft opened an internal incident, removed the bad domain from production, notified customers, and revoked the initially identified certificates plus additional ones it later found. Microsoft said the problem was caused by a domain that had been mistakenly added during a manual April 2020 domain-validation process, and that its internal linting did not detect the TLD problem. Over the course of the thread, Microsoft described several remediation steps, including revalidating domains, revoking impacted certificates, improving domain-validation automation, adding CAA checks, and updating its CPS. Microsoft later stated that the 8 certificates originally disclosed were the only certificates issued for the bad domains in this incident, and it ultimately removed the DNS Operator exception from its CPS. The bug was later marked resolved, with Microsoft asking for closure after completing its short-term repair items.
- An external partner notified Microsoft about public TLS certificates issued for a problematic domain.
- Microsoft removed the bad domain from production and revoked the initially identified impacted certificates plus additional ones.
- Microsoft said the 8 disclosed certificates were the only certificates issued for the bad domains in this incident.
- Microsoft implemented CAA checks in production for all certificate issuances.
- Microsoft said it would remove the DNS Operator exception from its CPS.
- Microsoft Corporation — Microsoft explained that it learned of the issue from an outside partner, opened an internal incident, removed the bad domain from production, notified customers, revoked 8 certificates, and created this Bugzilla case.
- Community commenter — Ryan Sleevi asked for more detail about Microsoft’s domain validation process, controls, and documentation.
- Microsoft Corporation — Microsoft described the April 2020 manual domain-validation process, said the bad domain was missed during validation, and said the process lacked scalability and had linting/TLD-detection issues.
- Microsoft Corporation — Microsoft said 5 domains had been sent validation email to an improper contact, that the 8 disclosed certificates were the only impacted ones, and that it had updated its domain-validation process and planned CAA checks.
- Microsoft Corporation — Microsoft reported that it had updated its CPS to clarify CAA checks and continued work on automation and linting improvements.
- Microsoft Corporation — Microsoft described a manual DNS Operator exception process and said it used registrar/WhoIs lookups, domain-owner contact, CAA checks, and issuance linting.
- Microsoft Corporation — Microsoft said it would focus on determining whether an FQDN is operated by Microsoft DNS Servers on a per-FQDN basis and described the internal Corporate Domains Team process.
- Microsoft Corporation — Microsoft said it agreed the DNS Operator exception was problematic and would remove it from its CPS.