Microsoft PKI Services: Improper CRL Disclosure (IDP URL mismatch) for 12 New CAs
Microsoft PKI Services (MPS) opened this Bugzilla as part of its investigation into CRL disclosure issues in CCADB and to track a CRL Watch finding for “Issuing Distribution Point (IDP) does not contain expected URL” affecting 12 newly created CAs. MPS reported that these CAs used partitioned CRLs published across primary and secondary endpoints, but the CCADB CRL disclosures included only the primary CRL URLs, omitting the corresponding secondary CRL endpoint. MPS stated that CRLs were present and accessible, but the incomplete CCADB disclosure caused CRL Watch IDP URL mismatch alerts. After identifying the gap, MPS attempted remediation by updating CCADB with JSON arrays including both primary and secondary endpoints (about 200 CRL URLs), but the attempt was initially blocked by a character length limitation in the CCADB interface. MPS worked with CCADB administrators, who fixed the field limitation restrictions, and MPS then completed updates to the affected CCADB entries. MPS submitted a closure report stating that the related CRL Watch findings were resolved and requested closure; the bug is marked RESOLVED with resolution FIXED.
- Non-compliance period began for CRL disclosure handling for the affected CAs.
- MPS opened Bugzilla 2007221 to address improper CRL disclosures for 12 CAs.
- MPS discovered additional syntax issues with CRL URLs posted in CCADB while investigating CRL Watch findings.
- MPS identified the specific IDP mismatch issue as only primary CRL URLs were published in CCADB disclosures, with secondary URLs missing.
- MPS opened Bugzilla 2009542 and attempted to remediate by submitting expanded CCADB CRL JSON including both primary and secondary endpoints, but hit a CCADB character length limitation.
- CCADB administrators fixed the field limitation restrictions, enabling complete CRL JSON disclosure updates.
- MPS reported completion of all action items, including updating the 12 impacted CAs in CCADB with primary and secondary CRL URLs.
- MPS requested closure after submitting the closure report.
- Microsoft Corporation — Opened a preliminary incident report stating MPS found additional CRL URL syntax issues in CCADB via CRL Watch and created this bug to track the IDP URL mismatch for 12 new CAs.
- CCADB representative — Asked for additional information to determine how to categorize the incident (e.g., CRL failure vs disclosure failure vs other).
- Microsoft Corporation — Responded that MPS believed the issue was limited to additional syntax errors in CRL URLs posted in CCADB and did not see other problems at that time.
- Microsoft Corporation — Provided a full incident report explaining that CCADB disclosures included only primary CRL endpoints (secondary omitted), and remediation was initially blocked by a CCADB character length limitation.
- Microsoft Corporation — Reported weekly status updates including that CCADB administrators fixed field limitation restrictions and that work continued to update CCADB entries with the fix in place.
- Microsoft Corporation — Reported weekly status updates stating all action items were complete and closure report would be posted soon.
- Microsoft Corporation — Submitted the report closure summary stating CCADB disclosures were updated to include both primary and secondary CRL endpoints and CRL Watch findings were resolved, requesting closure.
- CCADB representative — Issued a final call for comments and indicated the incident report would be closed around 2026-02-16 if no comments were provided.
- Microsoft Corporation — Noted the closure report was submitted and asked to close if no other comments were provided.