← Microsoft Corporation cases
Bugzilla #2009543 Ca Certificate Compliance Incident Repository Issue

Microsoft PKI Services: CRL Watch “does not match CA subject” due to legacy CCADB entry (removed CA record)

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services (MPS) opened this Bugzilla after investigating CRL disclosure issues in CCADB and using the CRL Watch tool, which reported a “does not match CA subject” finding. During the investigation, MPS discovered additional syntax issues with CRL URLs posted in CCADB and determined this bug would specifically track the CRL Watch alert for “does not match CA subject.” MPS confirmed that the root in question, Microsoft ECC Root Certificate Authority 2017 (Version 1), had already been marked as “removed” in CCADB and therefore was not subject to CCADB Policy Section 6.2. MPS stated that the alert was a false positive caused by a legacy CCADB entry where the removed CA record (Version 1) contained the CRL associated with Version 2. To resolve the CRL Watch alert, MPS cleared the CRL field for the removed CA record (Version 1) in CCADB. The incident report concluded that no remediation actions were required because the CA was not out of compliance, and MPS requested closure; the bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:28 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.90 7 comments
Chronology
  1. MPS investigation identified additional syntax issues with CRL URLs posted in CCADB via CRL Watch.
  2. MPS opened related Bugzilla 2007221 to address improper CRL disclosure of several CAs.
  3. MPS confirmed the flagged root record (Version 1) was marked removed in CCADB and opened a CCADB root case to remove the full CRL for that record.
  4. CCADB admin removed the CRL from the removed root record (Version 1), clearing the CRL Watch alert.
Thread Activity
  1. Microsoft Corporation — Opened a preliminary incident report stating MPS found CRL Watch issues for “does not match CA subject” while investigating CRL disclosures in CCADB.
  2. CCADB representative — Asked whether the issue was a malformed CRL (CRL failure) or an erroneous CCADB disclosure (disclosure failure).
  3. Microsoft Corporation — Responded that the issue was believed to be limited to additional syntax errors in the CRL URLs posted in CCADB and that no problems were seen at that time.
  4. Microsoft Corporation — Submitted a full incident report concluding the CA record was already marked removed in CCADB and that the CRL Watch issue was resolved by clearing the CRL field for the removed record.
  5. Microsoft Corporation — Provided a report closure summary stating the alert was a false positive due to a legacy CCADB entry and requested closure.
  6. CCADB representative — Issued a final call for comments before closure around 2026-02-06.
  7. Microsoft Corporation — Noted the closure report was submitted and asked to close if no other comments were provided.
Participants
Microsoft Corporation CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 100% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2009545 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-11 · 100% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 100% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#2009539 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-17 · 100% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
#2009541 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-11 · 97% similar
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
#2008847 RESOLVED Incident Opened 2026-01-06 · Closed 2026-02-17 · 97% similar
Microsoft PKI Services: Sample Site Certificates expired
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 96% similar
Microsoft PKI Services: OCSP Non-Compliance
#1970968 RESOLVED Ca Certificate Compliance Opened 2025-06-06 · Closed 2025-07-08 · 96% similar
Microsoft PKI Services: Incorrect Revocation Reason Code

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action