Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme (CRL Watch unsupported protocol scheme)
Microsoft PKI Services (MPS) opened this Bugzilla after its investigation into CCADB CRL disclosures found additional syntax issues in CRL URLs posted in CCADB. MPS reported that on 2025-01-06 it discovered six “unsupported protocol scheme” findings flagged by the CRL Watch tool. The affected entries were for six CAs created in August 2025, and MPS stated that the CRL URL fields were left empty because no certificates had been issued from those CAs and no CRLs existed at the time. MPS concluded that this did not constitute noncompliance with CCADB Policy Section 6.2 because no certificates had been issued that would require CRL URL disclosure. To remediate the CRL Watch findings, MPS updated the CCADB records with full CRL URLs for the six CAs, which cleared the CRL Watch errors. MPS also reported updating internal procedures to require a defined placeholder or full CRL for CRL URL fields when a CRL is not present. The bug is resolved as FIXED.
- MPS created six CAs whose CRL URL fields were later populated as empty in CCADB because no certificates were issued.
- MPS became aware of CRL Watch flags for “unsupported protocol scheme” related to CRL URL syntax in CCADB.
- MPS updated CCADB with full CRL URLs for the six CAs, clearing the CRL Watch findings.
- The bug was resolved (FIXED).
- Microsoft Corporation — Opened a preliminary incident report stating CRL Watch showed six “unsupported protocol scheme” issues and that the bug would track those CRL Watch findings.
- CCADB representative — Asked for additional information to categorize the incident (e.g., CRL failure vs disclosure failure vs policy/process failure).
- Microsoft Corporation — Responded that the issue was believed to be limited to additional syntax errors in CRL URLs and that no problems were seen at that time.
- Microsoft Corporation — Provided a full incident report explaining the CRL URL fields were empty because no certificates were issued, stating this was not noncompliance with Section 6.2, and describing the CCADB updates that cleared CRL Watch.
- Microsoft Corporation — Reported weekly status that action items were complete and closure reporting would follow.
- Microsoft Corporation — Submitted a report closure summary stating the CCADB records were updated with valid CRL URLs and internal guidance/procedures were updated.
- CCADB representative — Issued a final call for comments and noted the incident report would be closed around 2026-02-11.
- Microsoft Corporation — Noted the closure report had been submitted and requested closure if no further comments were provided.