← Microsoft Corporation cases
Bugzilla #1970968
Certificate Problem Report
Microsoft PKI Services: Incorrect Revocation Reason Code
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services incorrectly selected the revocation reason code 'affiliationChanged' instead of 'superseded' while revoking a batch of 25,000 certificates on June 5, 2025. This error was identified shortly after the revocation, leading to an internal incident review. The root cause was traced to the revocation tooling defaulting to 'affiliationChanged' as the pre-selected option, which was not adequately checked by peer reviewers. Remediation actions have been completed, including updating the revocation tooling and internal procedures to prevent future occurrences.
Chronology
- Revocation batch executed with incorrect reason code.
- Non-compliance identified and internal incident review initiated.
- Remediation actions completed.
- Incident report closure requested.
Participants
CentralPKI@microsoft.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Microsoft PKI Services: Failure to publish Full Incident Report for Bugzilla 2021175 within 14 days
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Pre-Sign Linting Validation did not occur in ICA creation
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829