Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
Microsoft PKI Services identified a failure to update their Certification Practices Statement (CPS) regarding the Subscriber Certificate Maximum Validity Period, which did not reflect the updated Baseline Requirements effective September 1, 2020. The issue was discovered internally on February 4, 2021, during the preparation of a new CPS. Microsoft confirmed that their certificate issuance processes remained compliant with the updated validity period. They have since posted an updated CPS and implemented new procedures to ensure compliance with industry changes. The bug has been resolved with the implementation of these corrective actions.
- Microsoft PKI Services became aware of the issue with their CPS.
- Microsoft finalized a new version of the CPS for review.
- Microsoft updated their Policy Document Review procedures.
- The bug was scheduled for closure.
- Microsoft Corporation — Microsoft PKI Services reported the issue and outlined their response timeline.
- Mozilla representative — Mozilla acknowledged Microsoft's proactive steps in resolving the issue.
- Microsoft Corporation — Microsoft posted an updated CPS to their repository.
- Microsoft Corporation — Microsoft reported updates to their Policy Document Review procedures.
- Community commenter — Questions were raised about the root cause and new processes.
- Mozilla representative — Mozilla planned to close the bug.