← Microsoft Corporation cases
Bugzilla #1705419
Certificate Problem Report
Microsoft PKI Services: Underscore in SAN
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services encountered an issue where two certificates were issued containing underscores in the Subject Alternative Name (SAN), which is not compliant with CAB Forum guidelines. The problem was reported by DigiCert, leading to an immediate internal investigation. Microsoft halted all certificate issuance and revoked the affected certificates. They are also implementing a new linting tool, ZLint, to prevent future occurrences. The root cause was identified as a flaw in their internal linting tool that failed to check for underscores correctly.
Chronology
- Bugzilla incident opened
- Issue reported by DigiCert
- Internal investigation started
- Service shut down procedure began
- Affected certificates revoked
- Post issuance linting with ZLint implemented
Participants
Michel Le Bihan
John Mason
Mohan R
Ryan Sleevi
External References
Similar Local Cases
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
Microsoft PKI Services: Unrevoked 4 intermediate certificates
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
Microsoft PKI Services: OCSP Responder does not know a Certificate
Microsoft PKI Services: "unknown" OCSP response for issued certificates
Telekom Security: Multiple commonName in certificates
e-commerce monitoring GmbH: CN domain not in SAN