← Microsoft Corporation cases
Bugzilla #1711147 Certificate Problem Report

Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services identified eight Intermediate CAs that were mis-issued due to missing certificate policy extensions, violating Baseline Requirements. The issue was reported by their WebTrust auditor on May 4, 2021. Microsoft promptly acknowledged the issue, revoked the affected certificates, and implemented a post-issuance check using Zlint to prevent future occurrences. They are also working on enhancing their issuance processes, including plans for automated pre-issuance linting by December 2022.

Model: gpt-4o-mini Generated: 2026-06-13 21:14 UTC Confidence: 0.95
Chronology
  1. Issue reported to Microsoft PKI Services by auditor.
  2. Revocation of all eight affected ICAs completed.
  3. Detailed root cause analysis provided.
  4. Plans for automated pre-issuance linting confirmed.
Participants
John Mason
External References
Similar Local Cases
#1705419 RESOLVED Certificate Problem Report Opened 2021-04-15 · Closed 2023-02-22 · 65% similar
Microsoft PKI Services: Underscore in SAN
#1718991 RESOLVED Certificate Problem Report Opened 2021-07-02 · Closed 2024-05-09 · 63% similar
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
#1793443 RESOLVED Certificate Problem Report Opened 2022-10-03 · Closed 2024-05-09 · 60% similar
Microsoft PKI Services: "unknown" OCSP response for issued certificates
#1740585 RESOLVED Certificate Problem Report Opened 2021-11-10 · Closed 2024-05-09 · 60% similar
Microsoft PKI Services: Unrevoked 4 intermediate certificates
#1879552 RESOLVED Certificate Problem Report Opened 2024-02-09 · Closed 2024-03-29 · 58% similar
Microsoft PKI Services: OCSP Responder does not know a Certificate
#2008847 RESOLVED Certificate Problem Report Opened 2026-01-06 · Closed 2026-02-17 · 56% similar
Microsoft PKI Services: Sample Site Certificates expired
#1598390 RESOLVED Certificate Problem Report Opened 2019-11-21 · Closed 2024-05-09 · 56% similar
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
#1884461 RESOLVED Certificate Problem Report Opened 2024-03-08 · Closed 2024-05-20 · 55% similar
Microsoft PKI Services: CA Certificates not published in DER Encoded Format

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action