← Microsoft Corporation cases
Bugzilla #1706860 Certificate Misissuance

Microsoft PKI Services: Certificate Mis-Issuance, DNSName is not FQDN, Preferred Name Syntax

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services identified three certificates that were mis-issued due to a DNSName not being a Fully Qualified Domain Name (FQDN), specifically due to a hyphen at the end of a label in the Subject Alternative Name (SAN). The issue was discovered on April 20, 2021, during an investigation of preferred name syntax errors. All three certificates were revoked within 24 hours of discovery, and Microsoft has since updated their internal linting tools to prevent future occurrences. A review confirmed no additional certificates with similar issues were found.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Confidence: 1.00
Chronology
  1. Bugzilla incident 1705419 opened.
  2. Discovered three mis-issued certificates.
  3. Confirmed all three certificates were revoked.
  4. Completed review of all issued certificates, confirming no additional issues.
  5. Bug closure anticipated unless further issues arise.
Participants
John Mason
Related Bugzilla IDs Mentioned
Similar Local Cases
#1644936 RESOLVED Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 63% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1670337 RESOLVED Certificate Misissuance Opened 2020-10-09 · Closed 2024-01-16 · 60% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD
#1674561 RESOLVED Certificate Misissuance Opened 2020-10-31 · Closed 2023-02-22 · 54% similar
Microsoft PKI Services: DV certificate issued with OV fields
#1979475 RESOLVED Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 53% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#2032476 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-07 · 48% similar
Microsoft PKI Services: Misissuance detected by PKIMetal
#1752670 RESOLVED Certificate Misissuance Opened 2022-01-29 · Closed 2024-05-09 · 45% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1750631 RESOLVED Certificate Misissuance Opened 2022-01-17 · Closed 2024-06-30 · 45% similar
SSL.com: Issuance of TLS certificates with domain validation methods prohibited by SC-45
#1785865 RESOLVED Certificate Misissuance Opened 2022-08-18 · Closed 2024-05-09 · 45% similar
NAVER Cloud Trust Services: DV certificate issued with no subject alternative name extension

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action