← Microsoft Corporation cases
Bugzilla #2009539 Incident

Microsoft PKI Services: Improper CRL URL disclosure in CCADB during transition to partitioned CRLs (Existing CAs)

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services (MPS) opened this bug as a self-disclosed incident after investigating CRL disclosure issues in CCADB and discovering additional syntax issues with CRL URLs posted in CCADB. MPS identified a CRL Watch finding for “Issuing Distribution Point does not contain expected URL” affecting Existing CAs that were transitioning from full CRLs to partitioned CRLs. For the first affected CA, MPS removed it from its production issuing rotation and updated it to support partitioned CRLs; CRL Watch then reported the issue until CCADB was updated. MPS determined the noncompliance was caused by a case mismatch between the CRL URL disclosed in CCADB and the URL present in the CRL’s Issuing Distribution Point during the transition. MPS updated the CCADB entry with partitioned CRL URLs that matched byte-for-byte (including correct casing), which cleared the CRL Watch alert for that CA, and repeated the process for additional CAs. The bug was resolved as FIXED, with action items completed and a closure report submitted requesting closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:26 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.90 9 comments
Chronology
  1. MPS configured an Existing CA for CRL partitioning and removed it from the production issuing rotation.
  2. MPS updated CCADB for the CA with partitioned CRL URLs matching the CRL Issuing Distribution Point URLs byte-for-byte, clearing the CRL Watch alert.
  3. MPS configured another Existing CA for CRL partitioning and updated CCADB with byte-for-byte partitioned CRL URLs.
  4. MPS submitted the closure report and requested the bug be closed if no further comments were provided.
Thread Activity
  1. Microsoft Corporation — MPS reported that CRL Watch detected “Issuing Distribution Point does not contain expected URL” for Existing CAs due to additional syntax issues in CRL URLs posted in CCADB and described initial remediation steps.
  2. CCADB representative — CCADB incident reporting asked for more information to categorize the incident (e.g., CRL failure vs disclosure/process failure).
  3. Microsoft Corporation — MPS clarified it believed the issue was limited to additional syntax errors in CRL URLs listed in CCADB and not problems with the CRL files themselves.
  4. Microsoft Corporation — MPS provided the full incident report, stating the primary issue was a case mismatch between the CCADB-disclosed CRL URL and the CRL’s Issuing Distribution Point URL, and described remediation and planned updates for remaining CAs.
  5. Microsoft Corporation — MPS reported weekly status, including confirmation from CCADB that the 7-day disclosure requirement applies when an Existing CA issues its first certificate with updated CRL URLs.
  6. Microsoft Corporation — MPS reported completion of action items and stated all items associated with the bug were complete.
  7. Microsoft Corporation — MPS posted the report closure summary, including root cause (case mismatch) and remediation (byte-for-byte CCADB updates with correct casing).
  8. CCADB representative — CCADB issued a final call for comments and indicated the incident report would be closed around 2026-02-16.
  9. Microsoft Corporation — MPS stated the closure report was submitted and asked for closure if no other comments were provided.
Participants
Microsoft Corporation CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 100% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 100% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 99% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 97% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2009541 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-11 · 96% similar
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
#2008847 RESOLVED Incident Opened 2026-01-06 · Closed 2026-02-17 · 96% similar
Microsoft PKI Services: Sample Site Certificates expired
#2007221 RESOLVED Incident Opened 2025-12-20 · Closed 2026-03-02 · 88% similar
Microsoft PKI Services: Improper Disclosure of CRL
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 87% similar
Microsoft PKI Services: OCSP Non-Compliance

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action