← Microsoft Corporation cases
Bugzilla #1962830
Certificate Problem Report
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services made a configuration change that removed the OCSP URI from Subscriber certificates issued by four publicly trusted TLS Issuing CAs, which did not comply with the active Certificate Practice Statement (CPS) at the time. This non-compliance was identified on April 25, 2025, and all impacted certificates were revoked the same day. The incident stemmed from a lack of defined requirements to review the CPS before implementing changes, leading to a race condition between the CA change and the CPS update. Remediation steps have been implemented to prevent future occurrences.
Chronology
- Non-compliance began with the issuance of certificates without OCSP URI.
- New CPS version allowing OCSP URI to be optional was published.
- Non-compliance was identified and all impacted certificates were revoked.
Participants
Microsoft PKI Services
u654666@disabled.tld
External References
Similar Local Cases
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
Microsoft PKI Services: CA Certificates not published in DER Encoded Format
Microsoft PKI Services: Policy document bug
Microsoft: improper disclosure of CRL
Microsoft PKI Services: CRL Publication Failures
Microsoft PKI Services: Invalid Email Address for CPRs
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Underscore in SAN