← Microsoft Corporation cases
Bugzilla #1974592
Certificate Problem Report
Microsoft PKI Services: Pre-Sign Linting Validation did not occur in ICA creation
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services issued five new intermediate certificate authorities (ICAs) from Microsoft TLS RSA Root G2 without the required pre-sign linting validation, violating compliance expectations. The issue was identified during a post-issuance review on June 26, 2025, and all impacted ICAs were revoked by July 1, 2025. The root cause was a misconfiguration in the administrative tool that set the linting requirement flag to false. Remedial actions included updating the configuration management tool, improving UI visibility for critical settings, and expanding regression testing.
Chronology
- Non-compliance identified during post-issuance review.
- Impacted ICAs revoked.
- Closure report submitted.
Participants
CentralPKI@microsoft.com
External References
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: OCSP Non-Compliance
Microsoft PKI Services: Incorrect Revocation Reason Code
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs