Microsoft PKI Services: CA certificates published via AIA were PEM-encoded instead of DER-encoded
Microsoft PKI Services discovered that 8 CA certificates published to its AIA repository were PEM encoded instead of DER encoded, which did not comply with RFC 5280 Section 4.2.2.1. The certificates were published to the AIA URIs by 2023-07-07, and Microsoft stated its AIA publishing tools/process did not detect that the files were not DER encoded. Microsoft reported that the only known impact was from one Microsoft service that implemented custom certificate chaining validation expecting DER-formatted certificates in the AIA path, and Microsoft said it did not stop issuance because the certificates were not malformed. Microsoft started mitigation by replacing the 8 PEM-encoded files with new DER-encoded files at the same AIA locations using a staged deployment approach. Microsoft also updated its AIA publishing process to check for DER encoding. The bug was later updated to indicate both repair items were completed, and Mozilla asked whether there were objections to closing the incident around 5-Apr-2024; the bug is currently marked RESOLVED with resolution FIXED.
- Microsoft PKI Services published 8 CA certificates to the AIA file repository, but the files were PEM encoded rather than DER encoded.
- Microsoft PKI Services confirmed the 8 AIA-published files were not DER encoded.
- Microsoft completed the replacement of the 8 PEM-encoded AIA files with DER-encoded files at the same AIA locations.
- Microsoft completed updates to its AIA publishing process to check for DER encoding.
- Microsoft reported all repair items were completed and requested the incident be resolved.
- Disabled representative — Opened a draft incident report stating Microsoft self-identified that 8 AIA-published CA certificate files were PEM encoded instead of DER encoded and outlined mitigation and action items.
- Community commenter — Asked whether the issue should also be considered a Digicert incident for certificates linked in the report.
- DigiCert — Confirmed the bug is both Digicert (root) and Microsoft (issuer) but noted Microsoft posted the bug because the issue was within Microsoft’s workflow.
- Community commenter — Suggested a separate bug might be required for Digicert and asked for confirmation.
- DigiCert — Responded that no separate bug is expected because Microsoft is a CA in the root program and Digicert is used only for ubiquity.
- Mm representative — Disputed the list of affected certificates, arguing the affected items should be those whose AIA URLs point to non-DER certificates.
- Disabled representative — Posted an updated incident report reiterating the PEM-vs-DER problem, the limited known impact, and the mitigation plan.
- Microsoft Corporation — Provided an update that one action item was completed and the other had a committed date to be added by 2024-03-29.
- Microsoft Corporation — Reported completion of all repair items and requested the incident be resolved.
- Mozilla representative — Asked whether there were objections to closing the incident around 5-Apr-2024.