← Microsoft Corporation cases
Bugzilla #1693930 Policy Compliance

Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services identified a failure to update their Certification Practices Statement (CPS) regarding Subscriber Certificate Maximum Validity Periods, which was not aligned with the Baseline Requirements effective September 1, 2020. The issue was discovered during the preparation of a new CPS on February 4, 2021. Microsoft confirmed that their certificate issuance processes remained compliant throughout this period, and no problematic certificates were issued. They have since updated their CPS and improved their policy document review procedures to prevent similar issues in the future.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Confidence: 0.90
Chronology
  1. Issue discovered during CPS review.
  2. Confirmed compliance with updated max validity period.
  3. Verified no certificates issued with longer validity than allowed.
  4. Finalized new CPS version for review.
  5. Posted updated CPS v3.1.8.
  6. Updated policy document review procedures.
Participants
John Mason Ben Wilson Ryan Sleevi
Similar Local Cases
#1693932 RESOLVED Policy Compliance Opened 2021-02-20 · Closed 2023-02-22 · 74% similar
Microsoft PKI Services: Policy Documentation, Failure to update Domain Validation Method
#1700809 RESOLVED Policy Compliance Opened 2021-03-25 · Closed 2023-02-22 · 69% similar
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
#1738778 RESOLVED Policy Compliance Opened 2021-11-01 · Closed 2023-02-22 · 59% similar
TWCA: Policy OID not set to indicate the assurance level to the issued certs
#1680378 RESOLVED Policy Compliance Opened 2020-12-02 · Closed 2023-02-22 · 58% similar
NetLock: Replacement of enduser certificates after the EVGL 1.7.4 self-audit
#1586795 RESOLVED Policy Compliance Opened 2019-10-07 · Closed 2023-02-22 · 57% similar
NetLock: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1705904 RESOLVED Policy Compliance Opened 2021-04-17 · Closed 2023-02-22 · 57% similar
KIR S.A.: CP/CPS contains noncompliant DV method, does not specify CAA domains
#1688215 RESOLVED Policy Compliance Opened 2021-01-22 · Closed 2023-02-22 · 56% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#1742195 RESOLVED Policy Compliance Opened 2021-11-20 · Closed 2023-02-22 · 56% similar
Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action