← Microsoft Corporation cases
Bugzilla #1979475 Certificate Misissuance

Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)

RESOLVED FIXED Microsoft Corporation
AI Summary

Microsoft PKI Services identified a compliance issue involving the issuance of 784 Public TLS end entity certificates that did not include the Basic Constraint extension, which is required by their Certificate Practice Statement (CPS). The issue was discovered through enhanced monitoring and all affected certificates were revoked promptly. The root cause was traced to legacy profiles that lacked the necessary extension, which were reused without proper validation against updated CPS requirements. Remediation actions have been implemented to prevent future occurrences, including a validation checklist and internal linting rules.

Model: gpt-4o-mini Generated: 2026-06-13 21:22 UTC Confidence: 1.00
Chronology
  1. Non-compliance start date
  2. Non-compliance identified
  3. All impacted certificates revoked
Participants
CentralPKI@microsoft.com
Similar Local Cases
#2032476 RESOLVED Certificate Misissuance Opened 2026-04-16 · Closed 2026-05-07 · 55% similar
Microsoft PKI Services: Misissuance detected by PKIMetal
#1644936 RESOLVED Certificate Misissuance Opened 2020-06-11 · Closed 2024-05-09 · 53% similar
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
#1670337 RESOLVED Certificate Misissuance Opened 2020-10-09 · Closed 2024-01-16 · 53% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD
#1706860 RESOLVED Certificate Misissuance Opened 2021-04-22 · Closed 2023-02-22 · 53% similar
Microsoft PKI Services: Certificate Mis-Issuance, DNSName is not FQDN, Preferred Name Syntax
#1674561 RESOLVED Certificate Misissuance Opened 2020-10-31 · Closed 2023-02-22 · 51% similar
Microsoft PKI Services: DV certificate issued with OV fields
#2011865 RESOLVED Certificate Misissuance Opened 2026-01-22 · Closed 2026-03-17 · 46% similar
TrustAsia: SSL DV Mis-issuance against CP/CPS (IPAddress)
#1753287 RESOLVED Certificate Misissuance Opened 2022-02-02 · Closed 2024-07-08 · 45% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#1696872 RESOLVED Certificate Misissuance Opened 2021-03-08 · Closed 2025-03-20 · 45% similar
FNMT: Missisuance of web site certificates without CA/Browser Forum’s reserved policy OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action