← Microsoft Corporation cases
Bugzilla #1990801
Certificate Problem Report
Microsoft: improper disclosure of CRL
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services encountered an issue with the formatting of a JSON array for the partitioned CRL of the 'Microsoft TLS G2 ECC CA OCSP 06' CA. The error, which involved missing bracket symbols, was identified on September 25, 2025, after being reported by a user. The issue was resolved the same day. The incident highlighted gaps in JSON validation processes both before and after updates to the CCADB, prompting Microsoft to implement remediation actions, including automated validation checks and a feature enhancement request for CCADB.
Chronology
- Microsoft added 12 new CA certs to CCADB and updated metadata.
- Issue identified and resolved regarding the improperly formatted JSON array.
Participants
Andrew Ayer
Microsoft PKI Services
External References
Similar Local Cases
Microsoft PKI Services: Policy document bug
Microsoft PKI Services: "unknown" OCSP response for issued certificates
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: OCSP Responder does not know a Certificate
Microsoft PKI Services: Incorrect Revocation Reason Code