← Microsoft Corporation cases
Bugzilla #2008847 Incident

Microsoft PKI Services: Sample Site Certificates expired

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services reported a compliance incident involving its Sample Site certificates for two Microsoft root certificates (“Microsoft RSA Root Certificate Authority 2017” and “Microsoft ECC Root Certificate Authority 2017”). Microsoft PKI Services became aware on 2025-12-29 that the Sample Sites had expired “valid” certificate samples and expired “revoked” certificate samples, which it stated was out of compliance with Section 2.2 (Publication of information) of the CA/Browser Forum Baseline Requirements. On 2025-12-29 at ~5:46 PM PST, Microsoft PKI Services updated all impacted Sample Site certificates, remediating the “valid” certificate samples the same day. The “revoked” certificate samples were updated on the repository at the same time, but the certificates themselves were not revoked until 2025-12-30 at ~12:00 PM PST. A contributor factor cited in the incident report was the lack of monitoring or alerting for sample site certificate validity periods. Microsoft PKI Services later reported that it enabled certificate expiration monitoring and alerting for all sample site certificates and updated documentation to help mitigate sample-site certificate rotation incidents, and it requested closure; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:25 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.90 10 comments
Chronology
  1. Sample Site certificates for “valid” and “revoked” expired for two Microsoft root certificates.
  2. Microsoft PKI Services became aware that Sample Site certificate samples had expired and renewed/posted updated Sample Site certificates.
  3. Microsoft PKI Services revoked the affected “revoked” sample certificates.
  4. Microsoft PKI Services submitted the closure report and requested closure.
Thread Activity
  1. Microsoft Corporation — Opened a preliminary incident report describing the expired Sample Site “valid” and “revoked” certificate samples and the remediation timeline.
  2. Community commenter — Requested that the incident be filed within 72 hours and asked for clearer details on when Microsoft became aware, remediated, and decided to report.
  3. Microsoft Corporation — Agreed and opened Bug 2009541 to track the failure to report within the required window.
  4. Microsoft Corporation — Provided a full incident report including root cause analysis and action items with due dates and statuses.
  5. Microsoft Corporation — Posted a weekly status update stating repair items were in progress and due dates would be provided.
  6. Microsoft Corporation — Posted weekly status update with action item statuses, including enabling cert expiry monitoring and alerting as complete.
  7. Microsoft Corporation — Reported completion of action items and stated a closure report would be posted soon.
  8. Microsoft Corporation — Submitted the report closure summary, requested closure, and stated monitoring/alerting and documentation updates were completed.
  9. CCADB representative — Issued a final call for comments and indicated the incident report would be closed around 2026-02-16.
  10. Microsoft Corporation — Reported that the closure report associated with this bug had been submitted and asked to close if no further comments were provided.
Participants
Microsoft Corporation Community commenter CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 100% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2009541 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-11 · 100% similar
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 97% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2009539 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-17 · 96% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 95% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 95% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#1962829 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2025-04-26 · Closed 2026-04-26 · 86% similar
Microsoft PKI Services: Policy document bug
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 86% similar
Microsoft PKI Services: OCSP Non-Compliance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action