← Microsoft Corporation cases
Bugzilla #1965612 Certificate Problem Report

Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829

IN PROGRESS FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services has faced challenges in revoking certificates in a timely manner, specifically failing to revoke certain certificates within the required five-day period as mandated by the Baseline Requirements. The incident was triggered by a typographical error in the Certificate Policy document, which led to confusion regarding the status of key usages in Subscriber certificates. As of the latest updates, Microsoft has revoked over 15 million certificates but still has approximately 31,000 active certificates pending revocation. The company has committed to completing all revocations by March 6, 2026, and is implementing measures to improve its certificate lifecycle management and revocation processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:20 UTC Confidence: 0.80
Chronology
  1. Preliminary Incident Report opened.
  2. Initial target date for revocation completion.
  3. Updated revocation status report issued.
  4. Final target date for all remaining revocations.
Participants
CentralPKI@microsoft.com chrome-root-program@google.com bwilson@mozilla.com rdaurne77@gmail.com malcolm.doody@gmail.com aaron@letsencrypt.org stephan@verbuecheln.ch lijun.liao@gmail.com
External References
Similar Local Cases
#2034251 RESOLVED Certificate Problem Report Opened 2026-04-22 · Closed 2026-05-13 · 75% similar
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
#1944436 RESOLVED Certificate Problem Report Opened 2025-01-28 · Closed 2025-04-03 · 72% similar
Microsoft PKI Services: Subject Key Identifiers in Some Subscriber Certificates Do Not Comply with RFC 5280
#2008847 RESOLVED Certificate Problem Report Opened 2026-01-06 · Closed 2026-02-17 · 66% similar
Microsoft PKI Services: Sample Site Certificates expired
#1886110 RESOLVED Certificate Problem Report Opened 2024-03-19 · Closed 2025-02-14 · 64% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1905419 RESOLVED Certificate Problem Report Opened 2024-06-28 · Closed 2024-10-31 · 60% similar
GoDaddy: Intermittent unauthorized OCSP response when certificate is freshly issued
#2009542 RESOLVED Certificate Problem Report Opened 2026-01-10 · Closed 2026-02-17 · 58% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#2009541 RESOLVED Certificate Problem Report Opened 2026-01-10 · Closed 2026-02-11 · 58% similar
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
#2026452 RESOLVED Certificate Problem Report Opened 2026-03-26 · Closed 2026-04-22 · 57% similar
Microsoft PKI Services: Failure to publish Full Incident Report for Bugzilla 2021175 within 14 days

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action