← Microsoft Corporation cases
Bugzilla #1965612 Delayed Revocation

Microsoft PKI Services delayed revocation after CPS typo affected RSA subscriber certificates

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services opened this case as a preliminary incident report after discovering that certificates issued under an erroneous CPS version were not revoked within the Baseline Requirements 5-day window. The underlying issue was a typo in CPS Version 3.2.4 stating that keyEncipherment was not present in RSA Subscriber certificates, even though Microsoft said it had always been present. Microsoft later filed a full incident report stating that revocation was delayed because revoking tens of millions of certificates at once would create very large CRLs and could impair client-side validation. Microsoft said it would revoke the affected certificates in batches, beginning on 2025-05-28 and continuing until 2025-11-15, while implementing CRL partitioning for the future. The thread also records Microsoft’s updates on revocation progress, action items, and follow-up questions from Chrome Root Program participants about automation, CRL sizing, and short-lived certificates.

Model: gpt-5.4-mini Generated: 2026-06-13 21:20 UTC Revised: 2026-06-16 14:26 UTC Confidence: 0.97 248 comments
Chronology
  1. Microsoft published CPS 3.2.4 with incorrect language about keyEncipherment in RSA Subscriber certificates.
  2. Microsoft published CPS 3.3.0, replacing tables with Appendix B language that still did not distinguish ECC and RSA public keys.
  3. A third-party researcher reported the CPS mismatch to Microsoft PKI Services.
  4. Microsoft opened the preliminary incident report for failure to revoke within 5 days.
  5. Microsoft published the full incident report and said revocation would be staged in batches.
  6. Microsoft began batch revocations.
  7. Microsoft stated that remaining revocations were expected to be completed by this date.
Thread Activity
  1. Disabled representative — Microsoft PKI Services said it had not revoked the affected certificates within 5 days and opened a preliminary incident report.
  2. Google representative — Chrome Root Program asked how Microsoft would handle automation, mass revocation, and future mitigation.
  3. Microsoft Corporation — Microsoft said it could auto-rotate certificates better now, but was evaluating revocation options because of CRL bloat and subscriber impact.
  4. Microsoft Corporation — Microsoft filed the full incident report, described the typo, and said revocation would be staged in batches starting 2025-05-28.
  5. Microsoft Corporation — Microsoft explained its batch strategy, said CRL partitioning was in testing, and updated action items and due dates.
  6. Microsoft Corporation — Microsoft said most impacted certificates were centrally renewable, that it had not triggered rotation, and that many affected certificates were no longer in use.
  7. Microsoft Corporation — Microsoft said a change advisory was not a freeze and would not stop unrelated revocations or certificate issuance.
  8. Microsoft Corporation — Microsoft posted a weekly status update saying it was still working through the action items.
Participants
Disabled representative 0266662 representative Community commenter Google representative Microsoft Corporation Thelettereph representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#1842121 RESOLVED Delayed Revocation Opened 2023-07-07 · Closed 2023-09-29 · 86% similar
Microsoft PKI Services: CRL Publication Failures
#1887705 RESOLVED Delayed Revocation Opened 2024-03-25 · Closed 2024-09-12 · 79% similar
Entrust: Delayed revocation of clientAuth TLS Certificates without serverAuth EKU
#1742195 RESOLVED Delayed Revocation Opened 2021-11-20 · Closed 2023-02-22 · 79% similar
Microsoft PKI Services: Failure to disclose Revocation of Intermediate CAs within 7 Days
#1872738 RESOLVED Delayed Revocation Opened 2024-01-02 · Closed 2025-02-14 · 79% similar
Buypass: Delayed revocation of TLS certificates
#1910805 RESOLVED Delayed Revocation Opened 2024-07-31 · Closed 2025-06-10 · 78% similar
DigiCert: Delayed revocation of 1910322
#1886110 RESOLVED Delayed Revocation Opened 2024-03-19 · Closed 2025-02-14 · 78% similar
TWCA: Revocation delay for TLS certificates with non-critical basicConstraints
#1887888 RESOLVED Delayed Revocation Opened 2024-03-26 · Closed 2025-02-28 · 78% similar
Hongkong Post: Delayed revocation of TLS certificates with basicConstraints not marked as critical
#1889062 RESOLVED Delayed Revocation Opened 2024-04-02 · Closed 2025-04-03 · 78% similar
GDCA: Delayed revocation of SSL/TLS certificates with Non-critical Basic Constraints

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action