Microsoft PKI Services: Pre-Sign Linting Validation did not occur in ICA creation
Microsoft PKI Services identified an internal compliance failure where five new intermediate certificate authorities (ICAs) were issued without the required pre-sign linting validation, violating CA/Browser Forum Baseline Requirements. This issue was discovered during a post-issuance review on June 26, 2025. The impacted ICAs were revoked on July 1, 2025, and no subscriber certificates were issued from them. Microsoft has implemented corrective actions, including updates to their configuration management tools and improvements in UI visibility for critical settings. All action items related to this incident have been completed, and a closure report has been submitted.
- Non-compliance identified during post-issuance review.
- Revocation of the five impacted ICAs.
- Closure report submitted.
- Microsoft Corporation — Opened Bugzilla bug with preliminary report.
- Microsoft Corporation — Submitted full incident report detailing the compliance failure.
- Microsoft Corporation — Provided report closure summary and confirmed completion of all action items.
- Microsoft Corporation — Requested closure of the bug as all action items were completed.