← Microsoft Corporation cases
Bugzilla #1904257 Certificate Misissuance

Microsoft PKI Services: Invalid Email Address for CPRs

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns delivery of Certificate Problem Reports (CPRs) to Microsoft PKI Services. The CPS section cited by the CA states that c**********i@microsoft.com is the email address for CPRs, but emails sent to that address were rejected as undeliverable with a “sender not allowed” error. The rejection was attributed to c**********l@microsoft.com, which was described as a distribution list member that forwards to internal addresses and sometimes blocks external email without notifying Microsoft. Microsoft reported that CPRs were still being properly delivered to c**********i@microsoft.com, but that some forwarded recipients may not receive the mail due to the blocking behavior. Microsoft investigated whether c**********l@microsoft.com should remain cc’ed and made a change to the membership so that c**********l@microsoft.com was no longer nested within c**********i@microsoft.com, with replication expected to stop the rejection emails. The bug was then proposed to be closed as “Invalid” or “Fixed” because the email address accomplished its intended purpose of contacting Microsoft, and Microsoft indicated they removed the nested distribution list and would not add more distribution lists as members. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.86 6 comments
Chronology
  1. A CPR email sent to Microsoft’s c**********i@microsoft.com was rejected as undeliverable due to a delivery restriction on a nested distribution list member.
  2. Microsoft modified the centralpki distribution list membership to remove the nested c**********l@microsoft.com distribution list member.
  3. The reporter indicated the issue could be closed as invalid/fixed and Microsoft confirmed the nested distribution list was removed and no further DL members would be added.
Thread Activity
  1. Mozilla representative — Reported that Microsoft PKI Services CPS points to c**********i@microsoft.com for CPRs, but emails to that address were rejected with a “sender not allowed” (550 5.7.133) error referencing c**********l@microsoft.com.
  2. Disabled representative — Stated that CPRs are properly delivered to c**********i@microsoft.com, and that c**********l@microsoft.com forwards to internal addresses that may block external email, causing rejection notifications.
  3. Disabled representative — Announced a membership change removing c**********l@microsoft.com from being nested within c**********i@microsoft.com, expecting rejection emails to stop after replication.
  4. Mozilla representative — Proposed closing the bug as “Invalid” or “Fixed” because the email address still contacted Microsoft, unless further input was received.
  5. Community commenter — Asked what actions Microsoft could take to prevent another distribution list member from blocking external email and confusing others.
  6. Disabled representative — Explained the blocking behavior was due to settings on a nested distribution list member and confirmed they removed that nested DL and are investigating possible design changes but are not committing yet.
Participants
Mozilla representative Disabled representative Community commenter
External References
Similar Local Cases
#1944436 RESOLVED Certificate Misissuance Opened 2025-01-28 · Closed 2025-04-03 · 93% similar
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
#1884461 RESOLVED Certificate Misissuance Opened 2024-03-08 · Closed 2024-05-20 · 83% similar
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
#1674561 RESOLVED Certificate Misissuance Opened 2020-10-31 · Closed 2023-02-22 · 73% similar
Microsoft PKI Services: DV certificate issued with OV fields
#1815534 RESOLVED Ca Certificate Compliance Certificate Misissuance Revocation Issue Opened 2023-02-07 · Closed 2024-04-17 · 73% similar
e-commerce monitoring GmbH: SCT in precertificate
#1645708 RESOLVED Certificate Misissuance Opened 2020-06-14 · Closed 2023-02-22 · 68% similar
QuoVadis: EV serialNumber with "none"
#1914466 RESOLVED Certificate Misissuance Opened 2024-08-22 · Closed 2024-10-02 · 68% similar
eMudhra emSign PKI Services: CA Certificates not published in DER Encoded Format
#1733000 RESOLVED Certificate Misissuance Opened 2021-09-28 · Closed 2023-02-22 · 67% similar
QuoVadis: revocation services validity set to expected value plus one second
#1910451 RESOLVED Certificate Misissuance Revocation Issue Opened 2024-07-29 · Closed 2024-08-21 · 67% similar
Sectigo: Missing character in subject:organizationName attribute value

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action