← Microsoft Corporation cases
Bugzilla #1693930 Policy Document Issue

Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services identified a failure to update their Certification Practices Statement (CPS) regarding the Subscriber Certificate Maximum Validity Period, which did not reflect the updated Baseline Requirements effective September 1, 2020. The issue was discovered internally on February 4, 2021, during the preparation of a new CPS. Microsoft confirmed that their certificate issuance processes remained compliant with the updated validity period. They have since posted an updated CPS and implemented new procedures to ensure compliance with industry changes. The bug has been resolved with the implementation of these corrective actions.

Model: gpt-4o-mini Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.85 11 comments
Chronology
  1. Microsoft PKI Services became aware of the issue with their CPS.
  2. Microsoft finalized a new version of the CPS for review.
  3. Microsoft updated their Policy Document Review procedures.
  4. The bug was scheduled for closure.
Thread Activity
  1. Microsoft Corporation — Microsoft PKI Services reported the issue and outlined their response timeline.
  2. Mozilla representative — Mozilla acknowledged Microsoft's proactive steps in resolving the issue.
  3. Microsoft Corporation — Microsoft posted an updated CPS to their repository.
  4. Microsoft Corporation — Microsoft reported updates to their Policy Document Review procedures.
  5. Community commenter — Questions were raised about the root cause and new processes.
  6. Mozilla representative — Mozilla planned to close the bug.
Participants
Microsoft Corporation Mozilla representative Community commenter
Similar Local Cases
#1705480 RESOLVED Ca Documents Policy Document Issue Opened 2021-04-15 · Closed 2023-02-22 · 78% similar
SECOM: CP/CPS does not clearly specify domain validation methods
#1688215 RESOLVED Ca Documents Incident Policy Document Issue Opened 2021-01-22 · Closed 2023-02-22 · 77% similar
Camerfirma: CP/CPS of Intesa Sanpaolo Sub-CA is Non-Compliant
#1817023 RESOLVED Policy Document Issue Opened 2023-02-15 · Closed 2024-05-09 · 77% similar
Microsoft PKI Services: Failure to modify policy documents within 365 days
#1713976 RESOLVED Policy Document Issue Opened 2021-06-02 · Closed 2023-02-22 · 77% similar
Amazon Trust Services: CP/CPS does not specify key compromise methods
#1886876 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-03-21 · Closed 2024-04-17 · 71% similar
Let's Encrypt: keyCompromise key blocking deviation from CP/CPS
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 71% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1711147 RESOLVED Self Reported Incident Opened 2021-05-13 · Closed 2023-02-22 · 71% similar
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
#1705419 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-15 · Closed 2023-02-22 · 70% similar
Microsoft PKI Services: Underscore in SAN

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action