← Microsoft Corporation cases
Bugzilla #2007221
Incident
Microsoft PKI Services: Improper Disclosure of CRL
RESOLVED
FIXED
Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
In December 2025, Microsoft PKI Services disclosed that they had improperly formatted the Certificate Revocation List (CRL) URLs for twelve newly created Certification Authorities (CAs) in the Common CA Database (CCADB). This issue was identified after receiving a Certificate Problem Reporting email indicating a potential violation of Section 6.2 of the CCADB Policy. Microsoft corrected the issue by updating the CCADB to include the correct JSON Array of Partitioned CRL URLs on December 19, 2025. They have since implemented process improvements to ensure compliance and prevent future discrepancies.
Chronology
- Microsoft PKI Services added twelve new CA certificates to CCADB.
- Microsoft received a report indicating potential non-compliance regarding CRL disclosures.
- Microsoft updated CCADB with the correct CRL URLs.
- All action items related to the incident were completed.
Thread Activity
- Microsoft Corporation — Preliminary Incident Report submitted detailing the improper CRL disclosure.
- Microsoft Corporation — Full Incident Report submitted with a timeline and impact analysis.
- Microsoft Corporation — Weekly Status Update confirming completion of all action items.
- Microsoft Corporation — Closure report submitted for the incident.
Participants
Microsoft Corporation
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: Failure to update action item status within 3 days
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Failure to disclose Unconstrained Intermediate within 7 Days