← Microsoft Corporation cases
Bugzilla #1700809
Self Reported Incident
Incident
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
RESOLVED
FIXED
Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
Microsoft PKI Services reported a failure to disclose eight newly created Unconstrained Intermediate CA certificates within the required seven-day timeframe. The issue was first identified by DigiCert on March 24, 2021, prompting Microsoft to initiate an internal investigation. Microsoft confirmed the problem was due to a process oversight related to the deployment of new Issuing CAs. They have since updated their processes to ensure timely disclosures and are exploring automation options to prevent future occurrences. The case has been resolved with the necessary changes implemented.
Chronology
- DigiCert reported the disclosure failure to Microsoft.
- Microsoft initiated an internal investigation.
- Microsoft confirmed process improvements and plans for automation.
Thread Activity
- Microsoft Corporation — Created attachments for the new CA certificates.
- Microsoft Corporation — Explained the process issue and steps taken to resolve it.
- Microsoft Corporation — Provided updates on collaboration with DigiCert for automation.
- Mozilla representative — Indicated intention to close the case unless further questions arise.
Participants
Microsoft Corporation
Community commenter
Mozilla representative
HARICA
External References
Similar Local Cases
Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work
HARICA: OCSP Responder Returned "Unauthorized" for Some Precertificates
Microsoft PKI Services: Failure to update action item status within 3 days
Microsoft PKI Services: Underscore in SAN
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
Microsoft PKI Services: "unknown" OCSP response for issued certificates
Microsoft PKI Services: Improper Disclosure of CRL