Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
This case involves a compliance issue identified in multiple Subscriber certificates issued by Microsoft PKI Services, where the subjectKeyIdentifier values were not unique as required by RFC 5280. The issue was reported by a researcher and triggered an internal investigation by Microsoft PKI Services. They confirmed that 19 certificates were affected, including 12 non-expired and 7 expired. Microsoft PKI Services has since revoked all impacted certificates and implemented additional validation checks to ensure compliance with RFC 5280 in future certificate requests. The case has been resolved with all action items completed.
- Certificate Problem Report received from a researcher.
- Final impacted certificate was revoked.
- Validation check for subjectKeyIdentifier compliance was implemented.
- Evaluation of all certificate properties completed.
- Final Action Item closed.
- Disabled representative — Preliminary incident report detailing the compliance issue.
- Disabled representative — Final incident report confirming the compliance issue and outlining the investigation.
- Disabled representative — Final Action Item was closed.