← Microsoft Corporation cases
Bugzilla #1962829 Certificate Problem Report

Microsoft PKI Services: Policy document bug

CLOSED FIXED Microsoft Corporation
AI Summary

This incident involved a typographical error in the Microsoft Public TLS CPS, where it incorrectly stated that the keyEncipherment key usage was not present in Subscriber certificates with RSA public keys. This mismatch led to a discrepancy between the CPS language and the actual issuance of Organization Validated TLS Subscriber Certificates. The error was identified during a review process and has since been addressed through various remediation actions, including formalizing review processes and updating documentation. All action items related to this incident have been completed, and Microsoft PKI Services is committed to ongoing improvements to prevent recurrence.

Model: gpt-4o-mini Generated: 2026-06-13 21:19 UTC Confidence: 0.95
Chronology
  1. Non-compliance start date
  2. Non-compliance end date
  3. Incident identified by third-party researcher
  4. All action items completed
Participants
Microsoft PKI Services Third-party researcher
External References
Similar Local Cases
#1990801 RESOLVED Certificate Problem Report Opened 2025-09-25 · Closed 2025-11-03 · 58% similar
Microsoft: improper disclosure of CRL
#1962830 RESOLVED Certificate Problem Report Opened 2025-04-26 · Closed 2025-06-20 · 58% similar
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
#2009539 RESOLVED Certificate Problem Report Opened 2026-01-10 · Closed 2026-02-17 · 53% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
#1970968 RESOLVED Certificate Problem Report Opened 2025-06-06 · Closed 2025-07-08 · 52% similar
Microsoft PKI Services: Incorrect Revocation Reason Code
#1884461 RESOLVED Certificate Problem Report Opened 2024-03-08 · Closed 2024-05-20 · 52% similar
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
#1586847 RESOLVED Certificate Problem Report Opened 2019-10-07 · Closed 2024-05-09 · 51% similar
Microsoft PKI Services: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy
#1598390 RESOLVED Certificate Problem Report Opened 2019-11-21 · Closed 2024-05-09 · 50% similar
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs
#1711147 RESOLVED Certificate Problem Report Opened 2021-05-13 · Closed 2023-02-22 · 50% similar
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action