← Microsoft Corporation cases
Bugzilla #2009543
Certificate Problem Report
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services (MPS) identified additional syntax issues with CRL URLs disclosed in CCADB during an investigation into improper CRL disclosures. The issue was linked to the Microsoft ECC Root Certificate Authority 2017, which had been marked as removed in CCADB. The investigation confirmed that there was no non-compliance with CCADB Policy Section 6.2, as the CRL field for the removed CA was cleared to resolve a false positive alert from CRL Watch. The case has been resolved with no further actions required.
Chronology
- MPS opened Bugzilla 2007221 regarding improper CRL disclosures.
- MPS discovered additional syntax issues with CRL URLs during investigation.
- Confirmed that the CA in question was marked 'removed' in CCADB.
- CRL field for the removed CA was cleared in CCADB.
- Closure report submitted; case closed.
Participants
CentralPKI@microsoft.com
incident-reporting@ccadb.org
External References
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: Pre-Sign Linting Validation did not occur in ICA creation
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: OCSP Non-Compliance