Microsoft PKI Services: Incorrect Revocation Reason Code
Microsoft PKI Services disclosed that it selected an incorrect Revocation Reason code while revoking a batch of certificates. The CA intended to use the “superseded” reason code but inadvertently marked the batch as “affiliationChanged” during a bulk revocation of approximately 25,000 certificates executed on 2025-06-05. The incident was detected shortly after the revocation, and the affected certificates were revoked with reason code “AffiliationChanged,” with no remaining valid certificates in the batch. Microsoft stated that issuance was not stopped because the failure occurred on the revocation side and certificate issuance processes and profiles were not impacted. Microsoft’s remediation included action items to remove “affiliationChanged” as the default reason code in revocation tooling, and to update internal SOPs and reviewer checklists to require explicit review of reason codes; Microsoft also discussed contextual validation as a remaining item that was later removed from public tracking as the risk was mitigated by other safeguards. The bug was resolved as FIXED, and Microsoft requested closure after reporting that the disclosed action items were completed.
- Microsoft PKI Services executed a bulk revocation of approximately 25,000 certificates using the wrong revocation reason code (“affiliationChanged”).
- Microsoft PKI Services identified the revocation reason code anomaly and initiated an internal incident review.
- Microsoft submitted the full incident report and supporting updates in the bug.
- The bug was resolved (FIXED) after the closure process.
- Microsoft Corporation — Microsoft provided a preliminary incident report stating it selected the wrong revocation reason code (“affiliationChanged” instead of “superseded”) while revoking a batch of 25,000 certificates and that it detected the issue shortly after executing the revocation.
- Microsoft Corporation — Microsoft posted a full incident report with impact details (25,000 certificates revoked; 0 remaining valid) and described the incident as part of remediation activities associated with Bug 1965612.
- Microsoft Corporation — Microsoft reported weekly updates including that it modified revocation tooling to remove “affiliationChanged” as the default reason code and updated SOPs/reviewer checklists, marking those items as Done.
- Microsoft Corporation — Microsoft stated it closed two repair items and that the remaining contextual validation item would be removed from public tracking because the risk was mitigated by other safeguards.
- Microsoft Corporation — Microsoft requested report closure, stating all disclosed action items were completed.
- CCADB representative — CCADB sent a final call for comments or questions before the incident report would be closed.
- Microsoft Corporation — Microsoft noted that the closure report had been submitted and asked to close if no other comments were provided.