Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
Microsoft PKI Services identified a compliance issue involving eight Intermediate CA certificates that were missing the required certificatePolicies extension, as mandated by the CA/Browser Forum Baseline Requirements. The issue was first reported by their WebTrust auditor on May 4, 2021. In response, Microsoft acknowledged the issue, revoked the affected certificates, and implemented a series of remediation steps, including updating their issuance processes to include post-issuance checks using Zlint. They also committed to enhancing their procedures to prevent similar issues in the future, including plans for automated pre-issuance linting by December 2022. The case has been resolved with the necessary actions taken.
- Issue reported to Microsoft PKI Services by their auditor.
- Revocation of all eight affected ICA certificates completed.
- Planned implementation of automated pre-issuance linting for CA certificates.
- Microsoft Corporation — Initial report of the incident and acknowledgment of the issue.
- Microsoft Corporation — Detailed root cause analysis provided, outlining the syntax error in the certificate policy extensions.
- Microsoft Corporation — Update on the implementation of new processes to prevent future mis-issuances.
- Microsoft Corporation — Confirmation of plans for automated pre-issuance linting and request to resolve the bug.