Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days
This case concerns Microsoft PKI Services’ CCADB disclosure of the revocation status for four intermediate CA (ICA) certificates. Microsoft stated that the four ICA certificates were revoked on 24 June 2021, but that the CCADB listing did not indicate they had been revoked. During investigation of Mozilla Bugzilla bug 1740585, Microsoft said it updated the CCADB entries to “Revoked” on 13 Nov 2021, and it believed the late CCADB status change may violate the Mozilla Root Store Policy requirement to upload changes to CCADB within 7 days. Microsoft also stated that it did not issue any certificates from the affected CAs because the CA certificates were revoked immediately after detecting the malformed-certificate issue. Microsoft requested comments on the incident and asked that it be marked resolved if no further discussion was needed. The bug was marked RESOLVED with resolution FIXED.
- Four intermediate CA certificates were created and revoked.
- The four intermediate CA certificates were manually loaded into CCADB.
- Microsoft corrected the CCADB entries for the four intermediate CA certificates to revoked status.
- Microsoft Corporation — Microsoft submitted an incident report describing that CCADB did not show the four ICA certificates as revoked and that it corrected the CCADB entries to revoked status on 13 Nov 2021, while noting this may be a violation of the 7-day disclosure requirement.
- Microsoft Corporation — Microsoft asked for comments on the incident report and requested the incident be marked resolved if there were no further comments.
- Mozilla representative — Mozilla indicated it would close the bug on Friday, 3-Dec-2021, unless further discussion was needed.