Microsoft PKI Services: CRL Watch “does not match CA subject” due to legacy CCADB entry (removed CA record)
Microsoft PKI Services (MPS) opened this Bugzilla after investigating CRL disclosure issues in CCADB and using the CRL Watch tool, which reported a “does not match CA subject” finding. During the investigation, MPS discovered additional syntax issues with CRL URLs posted in CCADB and determined this bug would specifically track the CRL Watch alert for “does not match CA subject.” MPS confirmed that the root in question, Microsoft ECC Root Certificate Authority 2017 (Version 1), had already been marked as “removed” in CCADB and therefore was not subject to CCADB Policy Section 6.2. MPS stated that the alert was a false positive caused by a legacy CCADB entry where the removed CA record (Version 1) contained the CRL associated with Version 2. To resolve the CRL Watch alert, MPS cleared the CRL field for the removed CA record (Version 1) in CCADB. The incident report concluded that no remediation actions were required because the CA was not out of compliance, and MPS requested closure; the bug is resolved as FIXED.
- MPS investigation identified additional syntax issues with CRL URLs posted in CCADB via CRL Watch.
- MPS opened related Bugzilla 2007221 to address improper CRL disclosure of several CAs.
- MPS confirmed the flagged root record (Version 1) was marked removed in CCADB and opened a CCADB root case to remove the full CRL for that record.
- CCADB admin removed the CRL from the removed root record (Version 1), clearing the CRL Watch alert.
- Microsoft Corporation — Opened a preliminary incident report stating MPS found CRL Watch issues for “does not match CA subject” while investigating CRL disclosures in CCADB.
- CCADB representative — Asked whether the issue was a malformed CRL (CRL failure) or an erroneous CCADB disclosure (disclosure failure).
- Microsoft Corporation — Responded that the issue was believed to be limited to additional syntax errors in the CRL URLs posted in CCADB and that no problems were seen at that time.
- Microsoft Corporation — Submitted a full incident report concluding the CA record was already marked removed in CCADB and that the CRL Watch issue was resolved by clearing the CRL field for the removed record.
- Microsoft Corporation — Provided a report closure summary stating the alert was a false positive due to a legacy CCADB entry and requested closure.
- CCADB representative — Issued a final call for comments before closure around 2026-02-06.
- Microsoft Corporation — Noted the closure report was submitted and asked to close if no other comments were provided.