← Microsoft Corporation cases
Bugzilla #1944436
Certificate Problem Report
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services issued multiple non-expired Subscriber certificates with identical Subject Key Identifier (SKI) values, violating RFC 5280 requirements for uniqueness. This issue arose from a manual Certificate Signing Request (CSR) process that allowed non-compliant SKI values derived from a null SHA-1 hash. A total of 19 certificates were identified as impacted, including 12 unexpired and 7 expired. Microsoft has since implemented additional validation checks to ensure compliance with RFC 5280 and prevent recurrence of similar issues.
Chronology
- Certificate Problem Report received from a researcher.
- Internal investigation initiated.
- Validation check for subjectKeyIdentifier compliance implemented.
- Evaluation of all certificate properties completed.
- Final incident report submitted.
Participants
u654666@disabled.tld
stephan@verbuecheln.ch
bwilson@mozilla.com
pete@cooperjr.name
johnmas@microsoft.com
aaron@letsencrypt.org
External References
Similar Local Cases
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829
Microsoft PKI Services: CRL Publication Failures
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
Microsoft PKI Services: Invalid Email Address for CPRs
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
IdenTrust: Unauthorized OCSP response on a Timestamp certificate