Microsoft PKI Services CPS policy document error on keyEncipherment
This case concerns a Microsoft PKI Services incident report about a CPS documentation error affecting its public TLS policy documents. Microsoft said CPS version 3.2.4 incorrectly stated that keyEncipherment was not present in subscriber certificates with RSA public keys, even though Microsoft had always included it, and later CPS 3.3.0 said keyEncipherment may be set without distinguishing RSA from ECC. Microsoft stated that the issue was identified on 2025-04-25 after a third-party researcher submitted a Certificate Problem Report directly to Microsoft. In the bug, Microsoft described the problem as a policy document management error and published incident reports, root cause information, and action items to improve document review, version control, and alignment between CPS content and linting. The thread also records that revocation questions arising from this incident were split into separate Bug 1965612, which Microsoft opened to track failure to revoke within five days. Microsoft later published CPS v3.3.2 and marked several remediation items complete, including clarifying RSA versus ECC keyEncipherment language and formalizing review of external Bugzilla incidents. The bug remained open with ongoing status updates about remaining action items, and the Bugzilla status shown is RESOLVED FIXED.
- Microsoft published Public TLS CPS 3.2.4 with a typo stating keyEncipherment was not present in subscriber certificates with RSA public keys.
- Microsoft published Public TLS CPS 3.3.0, replacing tables with Appendix B language stating keyEncipherment may be set but not distinguishing RSA from ECC.
- A third-party researcher sent a Certificate Problem Report to Microsoft identifying mismatches between subscriber certificates and CPS language.
- Microsoft published Public TLS CPS 3.3.1 retaining language that keyEncipherment may be set without distinguishing RSA from ECC.
- Microsoft opened Bug 1965612 to track failure to revoke impacted certificates within five days.
- Microsoft published CPS v3.3.2 and reported completion of related CPS clarification action items.
- Disabled representative — Microsoft opened the bug with a preliminary incident report describing a CPS typo and stating the source was a third-party Certificate Problem Report.
- Disabled representative — Microsoft posted a draft incident report with timeline details and said analysis and root cause work were still in progress.
- Internet Security Research Group — Aaron Gable asked whether Microsoft planned to revoke all affected RSA subscriber certificates issued while the CPS was incorrect.
- Disabled representative — Microsoft said it was still working on a response and would reply the next day.
- Disabled representative — Microsoft said it had opened Bug 1965612 to address failure to revoke within five days and would provide revocation details there.
- Disabled representative — Microsoft posted its full incident report, including affected certificate counts, related bugs, and initial root cause information.
- Community commenter — Wayne asked Microsoft to answer the revocation question directly and to explain its document review and comparison process.
- Disabled representative — Microsoft acknowledged the BR revocation requirement, said the five-day window had passed, and said it had not finalized a revocation plan.
- Google representative — Chrome Root Program asked detailed questions about related incidents, revocation expectations, and whether Microsoft's action items would meaningfully reduce recurrence.
- Microsoft Corporation — Microsoft responded that it had formal processes for its own bugs but only ad hoc review of other CAs' Bugzilla incidents, and said it would add a formal review process as a repair item.
- DigiCert — DigiCert said Microsoft is accountable for its own CPS updates, audits, and operations, while DigiCert maintains contractual compliance expectations for the cross-sign.
- Microsoft Corporation — Microsoft published action items including formalizing Bugzilla learnings, updating CP/CPS OID information, aligning linting with CP/CPS, and converting the CPS to Markdown.
- Google representative — Chrome Root Program asked follow-up questions about Microsoft's historical Bugzilla review practices, evaluation criteria, and additional technical controls.
- DigiCert — DigiCert described its oversight practices for externally operated cross-signed CAs, including regular meetings, audit review, and notice of policy changes.
- Microsoft Corporation — Microsoft posted a weekly status update, added an action item to evaluate CPS-to-lint translation, and corrected the reported non-compliance start date to 2024-07-21.
- Microsoft Corporation — Microsoft explained its prior ad hoc review of other CAs' Bugzilla incidents and said it would add review of new Bugzilla bugs to weekly compliance change control meetings.
- Microsoft Corporation — Microsoft accidentally posted a closure summary for a different incident in this bug.
- Community commenter — Wayne asked whether the closure summary had been intended for a different incident.
- Microsoft Corporation — Microsoft confirmed the closure summary was posted in error and belonged in Bug 1962830.
- Microsoft Corporation — Microsoft reported some action items complete, extended some CPS-related due dates, and said internal governance questions had delayed CPS publication.
- Microsoft Corporation — Microsoft said its new CPS v3.3.2 had been published and marked several CPS-related action items done.
- Microsoft Corporation — Microsoft said it had completed the action item to formalize Bugzilla bug learnings and requested less frequent update cadence.
- Community commenter — Wayne asked Microsoft to explain why one remaining action item's due date had been moved back by two months.
- Microsoft Corporation — Microsoft said it was still progressing through the last repair item with no major changes to report.