← Microsoft Corporation cases
Bugzilla #1700809
Policy Compliance
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft Corporation faced a compliance issue regarding the timely disclosure of new intermediate certificates. The problem was identified when DigiCert reported the failure to disclose two new Issuing CAs within the required 7-day timeframe. Microsoft acknowledged the oversight as a process issue and has since updated their procedures to ensure compliance with Mozilla's Root Store Policy. They have committed to improving their documentation and are exploring automation options to prevent future occurrences.
Chronology
- Issue reported by DigiCert via email.
- Microsoft confirmed the issue and updated CCADB with new CA certificates.
- Microsoft discussed potential automation solutions with DigiCert and Mozilla.
Participants
John Mason
Ryan Sleevi
Dimitris Zacharopoulos
Brett Wilson
External References
Similar Local Cases
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
Microsoft PKI Services: Policy Documentation, Failure to update Domain Validation Method
Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days
Microsoft PKI Services: Failure to modify policy documents within 365 days
Disig: CPS does not refer to BR domain validation methods
Sectigo: Missing Changelog in CPS
Microsoft PKI Services: Firewall log data retention
SECOM: CP/CPS does not clearly specify domain validation methods