← Microsoft Corporation cases
Bugzilla #2009539
Certificate Problem Report
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services (MPS) identified syntax issues with Certificate Revocation List (CRL) URLs in the CCADB while investigating improper CRL disclosures. The issue arose during the transition of existing CAs from full CRLs to partitioned CRLs, leading to a case mismatch between the URLs in CCADB and those in the CRLs. MPS has since updated the CCADB entries to ensure compliance with CCADB Policy Section 6.2. All action items related to this incident have been completed, and MPS has implemented measures to prevent recurrence.
Chronology
- First CA transitioned to partitioned CRLs, CRL Watch reported issue.
- CCADB updated with correct partitioned CRL URLs.
- Closure report submitted.
Participants
CentralPKI@microsoft.com
incident-reporting@ccadb.org
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: Incorrect Revocation Reason Code