← Microsoft Corporation cases
Bugzilla #1670337 Certificate Misissuance

Microsoft PKI Services mis-issuance involving non-public DNS names and domain validation failures

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services reported that it had issued public TLS certificates for a domain that was not public and therefore failed the DNSNames must have a valid Top-Level Domain check. The issue was first reported to Microsoft by an external partner on 2020-10-08, after which Microsoft opened an internal incident, removed the bad domain from production, notified customers, and revoked the initially identified certificates plus additional ones it later found. Microsoft said the problem was caused by a domain that had been mistakenly added during a manual April 2020 domain-validation process, and that its internal linting did not detect the TLD problem. Over the course of the thread, Microsoft described several remediation steps, including revalidating domains, revoking impacted certificates, improving domain-validation automation, adding CAA checks, and updating its CPS. Microsoft later stated that the 8 certificates originally disclosed were the only certificates issued for the bad domains in this incident, and it ultimately removed the DNS Operator exception from its CPS. The bug was later marked resolved, with Microsoft asking for closure after completing its short-term repair items.

Model: gpt-5.4-mini Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.96 56 comments
Chronology
  1. An external partner notified Microsoft about public TLS certificates issued for a problematic domain.
  2. Microsoft removed the bad domain from production and revoked the initially identified impacted certificates plus additional ones.
  3. Microsoft said the 8 disclosed certificates were the only certificates issued for the bad domains in this incident.
  4. Microsoft implemented CAA checks in production for all certificate issuances.
  5. Microsoft said it would remove the DNS Operator exception from its CPS.
Thread Activity
  1. Microsoft Corporation — Microsoft explained that it learned of the issue from an outside partner, opened an internal incident, removed the bad domain from production, notified customers, revoked 8 certificates, and created this Bugzilla case.
  2. Community commenter — Ryan Sleevi asked for more detail about Microsoft’s domain validation process, controls, and documentation.
  3. Microsoft Corporation — Microsoft described the April 2020 manual domain-validation process, said the bad domain was missed during validation, and said the process lacked scalability and had linting/TLD-detection issues.
  4. Microsoft Corporation — Microsoft said 5 domains had been sent validation email to an improper contact, that the 8 disclosed certificates were the only impacted ones, and that it had updated its domain-validation process and planned CAA checks.
  5. Microsoft Corporation — Microsoft reported that it had updated its CPS to clarify CAA checks and continued work on automation and linting improvements.
  6. Microsoft Corporation — Microsoft described a manual DNS Operator exception process and said it used registrar/WhoIs lookups, domain-owner contact, CAA checks, and issuance linting.
  7. Microsoft Corporation — Microsoft said it would focus on determining whether an FQDN is operated by Microsoft DNS Servers on a per-FQDN basis and described the internal Corporate Domains Team process.
  8. Microsoft Corporation — Microsoft said it agreed the DNS Operator exception was problematic and would remove it from its CPS.
Participants
Microsoft Corporation Community commenter Mm representative Binaryparadox representative Mozilla representative Lebihan representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1644936 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 100% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1706860 RESOLVED Certificate Misissuance Opened 2021-04-22 · Closed 2023-02-22 · 98% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSName is not FQDN, Preferred Name Syntax
#1705419 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-15 · Closed 2023-02-22 · 86% similar
Microsoft PKI Services: Underscore in SAN
#1884461 RESOLVED Certificate Misissuance Opened 2024-03-08 · Closed 2024-05-20 · 85% similar
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
#1676352 RESOLVED Certificate Misissuance Incident Opened 2020-11-10 · Closed 2023-02-22 · 85% similar
Microsec: Certificate validity period greater than 398 days
#1667430 RESOLVED Certificate Misissuance Opened 2020-09-25 · Closed 2023-02-22 · 84% similar
Camerfirma: Invalid stateOrProvinceName field
#1718991 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-07-02 · Closed 2024-05-09 · 84% similar
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
#1669594 RESOLVED Certificate Misissuance Opened 2020-10-06 · Closed 2023-02-22 · 84% similar
IdenTrust: Issuance of Subordinate CA’s Without EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action