← Microsoft Corporation cases
Bugzilla #2009542
Certificate Problem Report
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services (MPS) identified improper disclosures of Certificate Revocation Lists (CRLs) for 12 newly created CAs. The issue arose from the omission of secondary CRL URLs in the CCADB, which led to alerts from the CRL Watch tool regarding mismatched Issuing Distribution Points (IDP). MPS attempted to rectify the situation by updating the CCADB with both primary and secondary URLs, but faced a character length limitation in the interface. This limitation has since been resolved, allowing MPS to complete the necessary updates and align disclosures with CCADB policy requirements.
Chronology
- MPS opened Bug 2007221 related to improper CRL disclosures.
- Investigation revealed additional syntax issues with CRL URLs.
- Bug 2009542 was opened to track the IDP issue.
- CCADB administrators resolved the character length limitation.
- MPS updated CCADB with both primary and secondary CRL URLs.
Participants
CentralPKI@microsoft.com
External References
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: Incorrect Revocation Reason Code