← Microsoft Corporation cases
Bugzilla #1970968 Ca Certificate Compliance

Microsoft PKI Services: Incorrect Revocation Reason Code

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services disclosed that it selected an incorrect Revocation Reason code while revoking a batch of certificates. The CA intended to use the “superseded” reason code but inadvertently marked the batch as “affiliationChanged” during a bulk revocation of approximately 25,000 certificates executed on 2025-06-05. The incident was detected shortly after the revocation, and the affected certificates were revoked with reason code “AffiliationChanged,” with no remaining valid certificates in the batch. Microsoft stated that issuance was not stopped because the failure occurred on the revocation side and certificate issuance processes and profiles were not impacted. Microsoft’s remediation included action items to remove “affiliationChanged” as the default reason code in revocation tooling, and to update internal SOPs and reviewer checklists to require explicit review of reason codes; Microsoft also discussed contextual validation as a remaining item that was later removed from public tracking as the risk was mitigated by other safeguards. The bug was resolved as FIXED, and Microsoft requested closure after reporting that the disclosed action items were completed.

Model: gpt-5.4-nano Generated: 2026-06-13 21:21 UTC Revised: 2026-06-16 19:24 UTC Confidence: 0.90 8 comments
Chronology
  1. Microsoft PKI Services executed a bulk revocation of approximately 25,000 certificates using the wrong revocation reason code (“affiliationChanged”).
  2. Microsoft PKI Services identified the revocation reason code anomaly and initiated an internal incident review.
  3. Microsoft submitted the full incident report and supporting updates in the bug.
  4. The bug was resolved (FIXED) after the closure process.
Thread Activity
  1. Microsoft Corporation — Microsoft provided a preliminary incident report stating it selected the wrong revocation reason code (“affiliationChanged” instead of “superseded”) while revoking a batch of 25,000 certificates and that it detected the issue shortly after executing the revocation.
  2. Microsoft Corporation — Microsoft posted a full incident report with impact details (25,000 certificates revoked; 0 remaining valid) and described the incident as part of remediation activities associated with Bug 1965612.
  3. Microsoft Corporation — Microsoft reported weekly updates including that it modified revocation tooling to remove “affiliationChanged” as the default reason code and updated SOPs/reviewer checklists, marking those items as Done.
  4. Microsoft Corporation — Microsoft stated it closed two repair items and that the remaining contextual validation item would be removed from public tracking because the risk was mitigated by other safeguards.
  5. Microsoft Corporation — Microsoft requested report closure, stating all disclosed action items were completed.
  6. CCADB representative — CCADB sent a final call for comments or questions before the incident report would be closed.
  7. Microsoft Corporation — Microsoft noted that the closure report had been submitted and asked to close if no other comments were provided.
Participants
Microsoft Corporation CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 97% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 96% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 95% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 95% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#1962830 RESOLVED Ca Certificate Compliance Opened 2025-04-26 · Closed 2025-06-20 · 90% similar
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
#1974592 RESOLVED Ca Certificate Compliance Opened 2025-06-28 · Closed 2025-08-30 · 90% similar
Microsoft PKI Services: Pre-Sign Linting Validation did not occur in ICA creation
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 86% similar
Microsoft PKI Services: OCSP Non-Compliance
#1598390 RESOLVED Ca Certificate Compliance Opened 2019-11-21 · Closed 2024-05-09 · 79% similar
Microsoft PKI Services: Null Character Bug and Microsoft Root CAs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action