Microsoft PKI Services: CRL Publication Failures
This case reports CRL publication failures by Microsoft PKI Services that resulted in CRLs being published outside the CA/B Forum Baseline Requirements 4.9.7 timing constraints. Mozilla’s CA/B Forum requirement cited in the thread states that if a CA publishes a CRL, it must update and reissue CRLs at least once every seven days, and the nextUpdate value must not be more than ten days beyond the thisUpdate value. The issue was triggered when DigiCert notified Microsoft PKI Services that monitoring detected a delayed CRL publication for Microsoft Azure RSA TLS Issuing CA 07. Microsoft identified two related issues: a missing scheduled task/process for more frequent CRL publication on the newly deployed CA, and AD CS configuration where the CA software added padded time so CRL effective validity exceeded the intended window. Microsoft mitigated the issue by publishing a CRL for Microsoft Azure RSA TLS Issuing CA 07 with a nextUpdate timestamp less than 10 days from the thisUpdate timestamp, and by re-publishing the last remaining impacted CRL. The thread also states that CRL monitoring was updated to include CRLs for recently deployed CAs, and that all impacted CRLs were re-published to meet the stated requirement. The bug was marked RESOLVED with resolution FIXED, and Mozilla indicated it would be closed on 29-Sept-2023 after remediation steps were implemented.
- Microsoft Azure RSA TLS Issuing CA 07 published a CRL (last publication date noted in the thread).
- Internal incident was created after monitoring/operations investigation identified CRL timing concerns.
- DigiCert notified Microsoft PKI Services of delayed CRL publication; Microsoft published and re-published impacted CRLs to meet the CRL timing requirement.
- Microsoft confirmed final remediation deployment completed and asked whether the bug could be closed.
- Mozilla indicated it would close the bug on 29-Sept-2023.
- Disabled representative — Submitted a preliminary report describing delayed CRL publication and two identified causes, and provided a timeline and impacted CRL URLs.
- Disabled representative — Corrected an earlier statement about whether Microsoft Azure RSA TLS Issuing CA 07 had issued subscriber certificates.
- Disabled representative — Posted a final report with updated details, including that CRLs were re-published to meet Baseline Requirements 4.9.7 and that CRL monitoring was updated.
- Disabled representative — Reported that planning for additional automated validation of server settings was taking longer than expected and provided an anticipated commitment window.
- Disabled representative — Reported near-complete development of automated validation and expected final testing/deployment by 2023-08-14.
- Disabled representative — Reported testing completed and staying on track for deployment by 2023-08-14.
- Disabled representative — Confirmed final deployment component completion and asked if the bug could be closed (with a subsequent date correction).
- Disabled representative — Asked whether the bug could be closed after remaining remediation steps were implemented.
- Mozilla representative — Stated an intention to close the bug on Friday, 29-Sept-2023.