← Microsoft Corporation cases
Bugzilla #2009541
Certificate Problem Report
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services reported a failure to disclose an incident involving expired sample certificates on their public sites within the required 72-hour timeframe. The issue was identified on December 29, 2025, and while the expired certificates were promptly renewed, the Bugzilla report was not opened until January 9, 2026, due to delays in internal approval processes. This incident highlights a non-compliance with CCADB reporting obligations, specifically regarding timely disclosures. Remediation steps have been taken to clarify the escalation process for future incidents.
Chronology
- Microsoft PKI Services became aware of expired sample certificates.
- Bug 2008847 was opened to address the expired certificates.
- Bug 2009541 was opened to disclose the delayed reporting.
Participants
CentralPKI@microsoft.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
Microsoft PKI Services: Failure to publish Full Incident Report for Bugzilla 2021175 within 14 days
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829
Microsoft PKI Services: Incorrect Revocation Reason Code