Microsoft PKI Services delayed revocation after CPS typo affected RSA subscriber certificates
Microsoft PKI Services opened this case as a preliminary incident report after discovering that certificates issued under an erroneous CPS version were not revoked within the Baseline Requirements 5-day window. The underlying issue was a typo in CPS Version 3.2.4 stating that keyEncipherment was not present in RSA Subscriber certificates, even though Microsoft said it had always been present. Microsoft later filed a full incident report stating that revocation was delayed because revoking tens of millions of certificates at once would create very large CRLs and could impair client-side validation. Microsoft said it would revoke the affected certificates in batches, beginning on 2025-05-28 and continuing until 2025-11-15, while implementing CRL partitioning for the future. The thread also records Microsoft’s updates on revocation progress, action items, and follow-up questions from Chrome Root Program participants about automation, CRL sizing, and short-lived certificates.
- Microsoft published CPS 3.2.4 with incorrect language about keyEncipherment in RSA Subscriber certificates.
- Microsoft published CPS 3.3.0, replacing tables with Appendix B language that still did not distinguish ECC and RSA public keys.
- A third-party researcher reported the CPS mismatch to Microsoft PKI Services.
- Microsoft opened the preliminary incident report for failure to revoke within 5 days.
- Microsoft published the full incident report and said revocation would be staged in batches.
- Microsoft began batch revocations.
- Microsoft stated that remaining revocations were expected to be completed by this date.
- Disabled representative — Microsoft PKI Services said it had not revoked the affected certificates within 5 days and opened a preliminary incident report.
- Google representative — Chrome Root Program asked how Microsoft would handle automation, mass revocation, and future mitigation.
- Microsoft Corporation — Microsoft said it could auto-rotate certificates better now, but was evaluating revocation options because of CRL bloat and subscriber impact.
- Microsoft Corporation — Microsoft filed the full incident report, described the typo, and said revocation would be staged in batches starting 2025-05-28.
- Microsoft Corporation — Microsoft explained its batch strategy, said CRL partitioning was in testing, and updated action items and due dates.
- Microsoft Corporation — Microsoft said most impacted certificates were centrally renewable, that it had not triggered rotation, and that many affected certificates were no longer in use.
- Microsoft Corporation — Microsoft said a change advisory was not a freeze and would not stop unrelated revocations or certificate issuance.
- Microsoft Corporation — Microsoft posted a weekly status update saying it was still working through the action items.