← Microsoft Corporation cases
Bugzilla #1842121
Certificate Problem Report
Microsoft PKI Services: CRL Publication Failures
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services experienced issues with the timely publication of Certificate Revocation Lists (CRLs), failing to meet the CA/B Forum Baseline Requirements. The problems were identified through internal monitoring and external notifications from DigiCert. Two main issues were resolved: a missing scheduled task for a newly deployed CA and incorrect padding in the nextUpdate timestamps for CRLs. All impacted CRLs have since been re-published in compliance with the requirements.
Chronology
- Last publication date for Microsoft Azure RSA TLS Issuing CA 07
- Internal monitoring alerted about delayed CRL publication
- DigiCert notified about delayed CRL publication
- CRL file published with corrected timestamps
- Final component of automated validation deployment completed
- Case resolved and closed
Participants
u654666@disabled.tld
bwilson@mozilla.com
External References
Similar Local Cases
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
Microsoft PKI Services: Invalid Email Address for CPRs
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
Microsoft PKI Services: Improper Disclosure of CRL