← Microsoft Corporation cases
Bugzilla #1884461 Certificate Problem Report

Microsoft PKI Services: CA Certificates not published in DER Encoded Format

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services identified that eight certificates published to the AIA repository were incorrectly encoded in PEM format instead of the required DER format, violating RFC 5280 Section 4.2.2.1. This issue was self-identified and did not halt certificate issuance, as the certificates themselves were not malformed. The team initiated a staged deployment to replace the affected certificates and update their publishing process to prevent future occurrences. All action items related to this incident have been completed.

Model: gpt-4o-mini Generated: 2026-06-13 21:18 UTC Confidence: 1.00
Chronology
  1. Microsoft PKI Services published 8 CA certificates to the AIA file repository.
  2. Completed replacement of 8 old PEM encoded files with new DER encoded files.
  3. Updated AIA publishing process to check for DER encoding.
  4. All repair items related to the incident were completed.
Participants
u654666@disabled.tld amir@aaomidi.com jeremy.rowley@digicert.com agwa-bugs@mm.beanwood.com johnmas@microsoft.com bwilson@mozilla.com
External References
Similar Local Cases
#1944436 RESOLVED Certificate Problem Report Opened 2025-01-28 · Closed 2025-04-03 · 74% similar
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
#1904257 RESOLVED Certificate Problem Report Opened 2024-06-23 · Closed 2024-06-30 · 65% similar
Microsoft PKI Services: Invalid Email Address for CPRs
#1905419 RESOLVED Certificate Problem Report Opened 2024-06-28 · Closed 2024-10-31 · 64% similar
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
#1842121 RESOLVED Certificate Problem Report Opened 2023-07-07 · Closed 2023-09-29 · 64% similar
Microsoft PKI Services: CRL Publication Failures
#1962830 RESOLVED Certificate Problem Report Opened 2025-04-26 · Closed 2025-06-20 · 59% similar
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
#2034251 RESOLVED Certificate Problem Report Opened 2026-04-22 · Closed 2026-05-13 · 58% similar
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
#1902670 RESOLVED Certificate Problem Report Opened 2024-06-14 · Closed 2024-07-31 · 57% similar
Google Trust Services: SXG certificates issued without correctly checking CAA restrictions
#1897630 RESOLVED Certificate Problem Report Opened 2024-05-19 · Closed 2024-08-15 · 56% similar
Entrust: Jurisdiction issue in some EV TLS & Code Signing certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action