Microsoft PKI Services: Policy Documentation update for Domain Validation methods (CPS v3.1.7 to v3.1.8)
Microsoft PKI Services reported an issue with its Certification Practices Statement (CPS) documentation: in Section 3.2.2.4 for Domain Validation, the CPS did not clearly delineate that some domain validation methods used were deprecated. Microsoft stated it became aware of the issue on February 10, 2021 during discussions and review related to another Bugzilla task. Microsoft said it confirmed it did not use the deprecated Domain Validation methods after their deprecation dates and that it did not stop certificate issuance because it could verify its underlying validation processes followed the BRs. Microsoft finalized a new CPS version (v3.1.8) for review and approval with its Policy Authority and posted the updated CPS to its repository, stating it corrected the documentation structure and clarified which methods were used and when. Mozilla acknowledged the update and asked whether Microsoft had reviewed the CPS to ensure it reflects what Microsoft currently practices. Microsoft responded that it reflects what Microsoft can or will do, and it planned to remove the note on deprecated methods in the next 12 months when no valid certificates used those methods. The bug was resolved as FIXED.
- Microsoft became aware that its CPS documentation did not clearly delineate deprecated Domain Validation methods.
- Microsoft finalized a new CPS version for review and approval with its Policy Authority.
- Microsoft re-confirmed from its Domain Validation Cache that it did not use the deprecated methods after their deprecation dates.
- Microsoft expected to have the updated CPS posted to its repository (v3.1.8).
- Microsoft posted CPS v3.1.8 to its repository with the documentation issue corrected.
- Microsoft confirmed the CPS reflects current practice and planned removal of deprecated-method notes after certificates expire.
- Microsoft Corporation — Microsoft described how it became aware of the CPS documentation issue, its timeline, and its remediation plan to update the CPS.
- Mozilla representative — Mozilla thanked Microsoft for reporting and working on updating the CPS.
- Microsoft Corporation — Microsoft stated it posted updated CPS v3.1.8 to its repository with the issue corrected.
- Community commenter — Mozilla community member asked Microsoft to confirm the CPS reflects what it currently practices holistically.
- Microsoft Corporation — Microsoft confirmed it reviewed the CPS to reflect what it can or will do and explained how it will handle notes about deprecated methods.
- Mozilla representative — Mozilla indicated it would close the bug on 7-April-2021 unless additional issues remained.