← Microsoft Corporation cases
Bugzilla #1817023
Policy Compliance
Microsoft PKI Services: Failure to modify policy documents within 365 days
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services was notified by DigiCert that their policy documents were over 365 days old, violating the Baseline Requirements. The CA confirmed the issue and has since updated the Certificate Policy and Certification Practice Statement documents. Although this is a compliance issue, it does not impact certificate issuance. Microsoft has implemented a monitoring system to prevent future occurrences. The case has been resolved with the updated documents published and acknowledged.
Chronology
- CPS updates were finalized
- CP updates were finalized
- DigiCert notified Microsoft of outdated policy documents
- New versions of CP and CPS documents published
Participants
u654666@disabled.tld
johnmas@microsoft.com
bwilson@mozilla.com
External References
Similar Local Cases
Microsoft PKI Services: Firewall log data retention
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days
Microsoft PKI Services: Policy Documentation, Failure to update Domain Validation Method
IdenTrust: basicConstraints not flagged "Critical" Per Certification Practices Statement
Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days
Firmaprofesional: 2020 Audit Report Finding 1 out of 4
Chunghwa Telecom: outdated and stale policy documents disclosed to the CCADB