← Microsoft Corporation cases
Bugzilla #1884461 Certificate Misissuance

Microsoft PKI Services: CA certificates published via AIA were PEM-encoded instead of DER-encoded

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services discovered that 8 CA certificates published to its AIA repository were PEM encoded instead of DER encoded, which did not comply with RFC 5280 Section 4.2.2.1. The certificates were published to the AIA URIs by 2023-07-07, and Microsoft stated its AIA publishing tools/process did not detect that the files were not DER encoded. Microsoft reported that the only known impact was from one Microsoft service that implemented custom certificate chaining validation expecting DER-formatted certificates in the AIA path, and Microsoft said it did not stop issuance because the certificates were not malformed. Microsoft started mitigation by replacing the 8 PEM-encoded files with new DER-encoded files at the same AIA locations using a staged deployment approach. Microsoft also updated its AIA publishing process to check for DER encoding. The bug was later updated to indicate both repair items were completed, and Mozilla asked whether there were objections to closing the incident around 5-Apr-2024; the bug is currently marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.90 10 comments
Chronology
  1. Microsoft PKI Services published 8 CA certificates to the AIA file repository, but the files were PEM encoded rather than DER encoded.
  2. Microsoft PKI Services confirmed the 8 AIA-published files were not DER encoded.
  3. Microsoft completed the replacement of the 8 PEM-encoded AIA files with DER-encoded files at the same AIA locations.
  4. Microsoft completed updates to its AIA publishing process to check for DER encoding.
  5. Microsoft reported all repair items were completed and requested the incident be resolved.
Thread Activity
  1. Disabled representative — Opened a draft incident report stating Microsoft self-identified that 8 AIA-published CA certificate files were PEM encoded instead of DER encoded and outlined mitigation and action items.
  2. Community commenter — Asked whether the issue should also be considered a Digicert incident for certificates linked in the report.
  3. DigiCert — Confirmed the bug is both Digicert (root) and Microsoft (issuer) but noted Microsoft posted the bug because the issue was within Microsoft’s workflow.
  4. Community commenter — Suggested a separate bug might be required for Digicert and asked for confirmation.
  5. DigiCert — Responded that no separate bug is expected because Microsoft is a CA in the root program and Digicert is used only for ubiquity.
  6. Mm representative — Disputed the list of affected certificates, arguing the affected items should be those whose AIA URLs point to non-DER certificates.
  7. Disabled representative — Posted an updated incident report reiterating the PEM-vs-DER problem, the limited known impact, and the mitigation plan.
  8. Microsoft Corporation — Provided an update that one action item was completed and the other had a committed date to be added by 2024-03-29.
  9. Microsoft Corporation — Reported completion of all repair items and requested the incident be resolved.
  10. Mozilla representative — Asked whether there were objections to closing the incident around 5-Apr-2024.
Participants
Disabled representative Community commenter DigiCert Mm representative Microsoft Corporation Mozilla representative
Similar Local Cases
#1705419 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-15 · Closed 2023-02-22 · 95% similar
Microsoft PKI Services: Underscore in SAN
#1718991 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-07-02 · Closed 2024-05-09 · 95% similar
Microsoft PKI Services: Malformed ICAs (Key Usage Malformed)
#1674561 RESOLVED Certificate Misissuance Opened 2020-10-31 · Closed 2023-02-22 · 94% similar
Microsoft PKI Services: DV certificate issued with OV fields
#1421820 RESOLVED Ca Security Vulnerability Certificate Misissuance Opened 2017-11-29 · Closed 2022-11-14 · 87% similar
Microsoft DSRE PKI: Microsoft shares wildcard certificates among cloud instances
#1670337 RESOLVED Certificate Misissuance Opened 2020-10-09 · Closed 2024-01-16 · 85% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD
#1910322 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2025-06-18 · 84% similar
DigiCert: Random value in CNAME without underscore prefix
#1944436 RESOLVED Certificate Misissuance Opened 2025-01-28 · Closed 2025-04-03 · 84% similar
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
#1890896 RESOLVED Ca Documents Certificate Misissuance Opened 2024-04-11 · Closed 2024-08-15 · 83% similar
Entrust: CPS typographical (text placement) error

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action