← Microsoft Corporation cases
Bugzilla #1999850
Certificate Problem Report
Microsoft PKI Services: OCSP Non-Compliance
ASSIGNED
Microsoft Corporation
AI Summary
Microsoft PKI Services encountered an issue during the migration of their OCSP traffic to a new infrastructure. On November 10, 2025, it was discovered that OCSP responses included fractional seconds in critical fields, leading to TLS handshake failures for some relying parties. This non-compliance with RFC 5280 prompted a rollback to the legacy OCSP infrastructure, which has known compliance gaps. Microsoft is actively working to resolve the issue and plans to migrate back to the new infrastructure by June 30, 2026.
Chronology
- Migration to new OCSP infrastructure started
- Incident reported related to certificate validation errors
- Traffic moved back to legacy OCSP infrastructure
- Root cause confirmed as presence of fractional seconds
- Target date for migration to new infrastructure
Participants
CentralPKI@microsoft.com
External References
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Pre-Sign Linting Validation did not occur in ICA creation
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs