Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services reported a compliance incident involving its Sample Site certificates for two Microsoft root certificates (“Microsoft RSA Root Certificate Authority 2017” and “Microsoft ECC Root Certificate Authority 2017”). Microsoft PKI Services became aware on 2025-12-29 that the Sample Sites had expired “valid” certificate samples and expired “revoked” certificate samples, which it stated was out of compliance with Section 2.2 (Publication of information) of the CA/Browser Forum Baseline Requirements. On 2025-12-29 at ~5:46 PM PST, Microsoft PKI Services updated all impacted Sample Site certificates, remediating the “valid” certificate samples the same day. The “revoked” certificate samples were updated on the repository at the same time, but the certificates themselves were not revoked until 2025-12-30 at ~12:00 PM PST. A contributor factor cited in the incident report was the lack of monitoring or alerting for sample site certificate validity periods. Microsoft PKI Services later reported that it enabled certificate expiration monitoring and alerting for all sample site certificates and updated documentation to help mitigate sample-site certificate rotation incidents, and it requested closure; the bug is marked RESOLVED with resolution FIXED.
- Sample Site certificates for “valid” and “revoked” expired for two Microsoft root certificates.
- Microsoft PKI Services became aware that Sample Site certificate samples had expired and renewed/posted updated Sample Site certificates.
- Microsoft PKI Services revoked the affected “revoked” sample certificates.
- Microsoft PKI Services submitted the closure report and requested closure.
- Microsoft Corporation — Opened a preliminary incident report describing the expired Sample Site “valid” and “revoked” certificate samples and the remediation timeline.
- Community commenter — Requested that the incident be filed within 72 hours and asked for clearer details on when Microsoft became aware, remediated, and decided to report.
- Microsoft Corporation — Agreed and opened Bug 2009541 to track the failure to report within the required window.
- Microsoft Corporation — Provided a full incident report including root cause analysis and action items with due dates and statuses.
- Microsoft Corporation — Posted a weekly status update stating repair items were in progress and due dates would be provided.
- Microsoft Corporation — Posted weekly status update with action item statuses, including enabling cert expiry monitoring and alerting as complete.
- Microsoft Corporation — Reported completion of action items and stated a closure report would be posted soon.
- Microsoft Corporation — Submitted the report closure summary, requested closure, and stated monitoring/alerting and documentation updates were completed.
- CCADB representative — Issued a final call for comments and indicated the incident report would be closed around 2026-02-16.
- Microsoft Corporation — Reported that the closure report associated with this bug had been submitted and asked to close if no further comments were provided.