← Microsoft Corporation cases
Bugzilla #1718991
Certificate Problem Report
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services identified four Intermediate CAs that were mis-issued due to malformed Key Usage extensions. The issue was discovered on June 24, 2021, during a manual inspection of newly created certificates. The affected certificates were revoked shortly after issuance, and the root cause was traced to the configuration of internal software tools used for certificate template creation. Remediation steps have been implemented to prevent similar issues in the future.
Chronology
- Four Intermediate CA certificates issued and identified as malformed during inspection.
- Certificates revoked and template configuration corrected.
- All planned remediations completed.
Participants
John Mason
Ryan Sleevi
Kathleen Wilson
External References
Similar Local Cases
Microsoft PKI Services: Underscore in SAN
Microsoft PKI Services: Unrevoked 4 intermediate certificates
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
Microsoft PKI Services: "unknown" OCSP response for issued certificates
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
Microsoft PKI Services: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
Microsoft PKI Services: OCSP Responder does not know a Certificate
Microsoft DSRE PKI: problem reporting e-mail in CPS does not work