← Microsoft Corporation cases
Bugzilla #2007221
Certificate Problem Report
Microsoft PKI Services: Improper Disclosure of CRL
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services disclosed CRL information in CCADB that did not fully match the CRL Distribution Point (CDP) URLs published in certificates issued by twelve newly created CAs. This resulted in non-compliance with Section 6.2 of the CCADB Policy. The issue was identified following a Certificate Problem Reporting email, leading to an update on December 19, 2025, where the correct JSON Array of Partitioned CRL URLs was disclosed. Microsoft has since committed to ongoing monitoring and validation processes to ensure compliance with CCADB Policy requirements.
Chronology
- Microsoft PKI Services added 12 new CA certs to CCADB.
- Received a Certificate Problem Reporting email regarding CRL disclosure.
- Updated CCADB to include the correct JSON Array of Partitioned CRL URLs.
Participants
CentralPKI@microsoft.com
External References
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829