← Microsoft Corporation cases
Bugzilla #1999850 Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Policy Document Issue

Microsoft PKI Services OCSP non-compliance incident closed after all action items were completed

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services disclosed a self-reported compliance incident involving its OCSP responder infrastructure during a migration to new systems. The issue was that OCSP responses from the new infrastructure included fractional seconds in the thisUpdate, nextUpdate, revocationTime, and producedAt fields, which caused TLS handshakes to fail for some relying parties and was inconsistent with RFC 5280. Microsoft said it moved OCSP traffic back to its legacy infrastructure after discovering the problem, then worked through repair items to address the testing gap and complete the migration. In its closure summary, Microsoft said it updated the OCSP responder implementation to generate RFC 5280-compliant GeneralizedTime values without fractional seconds and expanded validation testing. Microsoft later stated that all action items were completed and requested closure, and CCADB issued a final call for comments before closing the report around 2026-07-01.

Model: gpt-5.4-mini Generated: 2026-06-13 21:24 UTC Revised: 2026-07-04 18:20 UTC Confidence: 0.98 22 comments
Chronology
  1. Migration to new OCSP infrastructure started.
  2. OCSP responses with fractional seconds caused TLS handshake failures for some relying parties.
  3. OCSP traffic was moved back to the legacy responder infrastructure.
  4. Microsoft said all action items were completed and submitted a closure summary.
  5. CCADB indicated the incident report would be closed around this date.
Thread Activity
  1. Microsoft Corporation — Microsoft filed a preliminary incident report describing the OCSP formatting issue and the fallback to legacy infrastructure.
  2. Microsoft Corporation — Microsoft filed the full incident report with the timeline, root cause analysis, and planned migration-back date.
  3. Microsoft Corporation — Microsoft extended the due date for action item #3 and said it would implement both an internal OCSP solution and a backup external implementation.
  4. Microsoft Corporation — Microsoft said all action items were completed and submitted a report closure summary.
  5. CCADB representative — CCADB issued a final call for comments or questions and said the incident report would be closed on approximately 2026-07-01.
Participants
Microsoft Corporation CCADB representative
Similar Local Cases
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 96% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 96% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 95% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 95% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 89% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
#1962829 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2025-04-26 · Closed 2026-04-26 · 87% similar
Microsoft PKI Services: Policy document bug
#2009539 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-17 · 87% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
#2008847 RESOLVED Incident Opened 2026-01-06 · Closed 2026-02-17 · 86% similar
Microsoft PKI Services: Sample Site Certificates expired

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action