Microsoft PKI Services: Improper CRL URL disclosure in CCADB during transition to partitioned CRLs (Existing CAs)
Microsoft PKI Services (MPS) opened this bug as a self-disclosed incident after investigating CRL disclosure issues in CCADB and discovering additional syntax issues with CRL URLs posted in CCADB. MPS identified a CRL Watch finding for “Issuing Distribution Point does not contain expected URL” affecting Existing CAs that were transitioning from full CRLs to partitioned CRLs. For the first affected CA, MPS removed it from its production issuing rotation and updated it to support partitioned CRLs; CRL Watch then reported the issue until CCADB was updated. MPS determined the noncompliance was caused by a case mismatch between the CRL URL disclosed in CCADB and the URL present in the CRL’s Issuing Distribution Point during the transition. MPS updated the CCADB entry with partitioned CRL URLs that matched byte-for-byte (including correct casing), which cleared the CRL Watch alert for that CA, and repeated the process for additional CAs. The bug was resolved as FIXED, with action items completed and a closure report submitted requesting closure.
- MPS configured an Existing CA for CRL partitioning and removed it from the production issuing rotation.
- MPS updated CCADB for the CA with partitioned CRL URLs matching the CRL Issuing Distribution Point URLs byte-for-byte, clearing the CRL Watch alert.
- MPS configured another Existing CA for CRL partitioning and updated CCADB with byte-for-byte partitioned CRL URLs.
- MPS submitted the closure report and requested the bug be closed if no further comments were provided.
- Microsoft Corporation — MPS reported that CRL Watch detected “Issuing Distribution Point does not contain expected URL” for Existing CAs due to additional syntax issues in CRL URLs posted in CCADB and described initial remediation steps.
- CCADB representative — CCADB incident reporting asked for more information to categorize the incident (e.g., CRL failure vs disclosure/process failure).
- Microsoft Corporation — MPS clarified it believed the issue was limited to additional syntax errors in CRL URLs listed in CCADB and not problems with the CRL files themselves.
- Microsoft Corporation — MPS provided the full incident report, stating the primary issue was a case mismatch between the CCADB-disclosed CRL URL and the CRL’s Issuing Distribution Point URL, and described remediation and planned updates for remaining CAs.
- Microsoft Corporation — MPS reported weekly status, including confirmation from CCADB that the 7-day disclosure requirement applies when an Existing CA issues its first certificate with updated CRL URLs.
- Microsoft Corporation — MPS reported completion of action items and stated all items associated with the bug were complete.
- Microsoft Corporation — MPS posted the report closure summary, including root cause (case mismatch) and remediation (byte-for-byte CCADB updates with correct casing).
- CCADB representative — CCADB issued a final call for comments and indicated the incident report would be closed around 2026-02-16.
- Microsoft Corporation — MPS stated the closure report was submitted and asked for closure if no other comments were provided.