← Microsoft Corporation cases
Bugzilla #1742195
Policy Compliance
Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services encountered an issue with the timely disclosure of the revocation of four Intermediate Certificate Authorities (ICAs). The revocations occurred on June 24, 2021, but the updates to the CCADB were not made until November 13, 2021, which raised concerns about compliance with Mozilla's Root Store Policy. The CA acknowledged the delay and provided a detailed timeline of events leading to the incident, including previous Bugzilla reports and discussions with Mozilla. The case has been resolved with the necessary updates made to the CCADB.
Chronology
- Four Intermediate CAs were revoked.
- CCADB entries for the CAs were corrected to Revoked status.
Participants
John Mason
External References
Similar Local Cases
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
Microsoft PKI Services: Policy Documentation, Failure to update Domain Validation Method
Microsoft PKI Services: Failure to modify policy documents within 365 days
Microsoft PKI Services: Firewall log data retention
Sectigo: Failure to revoke certificate with previously-compromised key within 24 hours
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
Sectigo: Missing Changelog in CPS