← Microsoft Corporation cases
Bugzilla #2009545 Ca Certificate Compliance Incident Repository Issue

Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme (CRL Watch unsupported protocol scheme)

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Microsoft PKI Services (MPS) opened this Bugzilla after its investigation into CCADB CRL disclosures found additional syntax issues in CRL URLs posted in CCADB. MPS reported that on 2025-01-06 it discovered six “unsupported protocol scheme” findings flagged by the CRL Watch tool. The affected entries were for six CAs created in August 2025, and MPS stated that the CRL URL fields were left empty because no certificates had been issued from those CAs and no CRLs existed at the time. MPS concluded that this did not constitute noncompliance with CCADB Policy Section 6.2 because no certificates had been issued that would require CRL URL disclosure. To remediate the CRL Watch findings, MPS updated the CCADB records with full CRL URLs for the six CAs, which cleared the CRL Watch errors. MPS also reported updating internal procedures to require a defined placeholder or full CRL for CRL URL fields when a CRL is not present. The bug is resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:29 UTC Revised: 2026-06-16 19:26 UTC Confidence: 0.90 8 comments
Chronology
  1. MPS created six CAs whose CRL URL fields were later populated as empty in CCADB because no certificates were issued.
  2. MPS became aware of CRL Watch flags for “unsupported protocol scheme” related to CRL URL syntax in CCADB.
  3. MPS updated CCADB with full CRL URLs for the six CAs, clearing the CRL Watch findings.
  4. The bug was resolved (FIXED).
Thread Activity
  1. Microsoft Corporation — Opened a preliminary incident report stating CRL Watch showed six “unsupported protocol scheme” issues and that the bug would track those CRL Watch findings.
  2. CCADB representative — Asked for additional information to categorize the incident (e.g., CRL failure vs disclosure failure vs policy/process failure).
  3. Microsoft Corporation — Responded that the issue was believed to be limited to additional syntax errors in CRL URLs and that no problems were seen at that time.
  4. Microsoft Corporation — Provided a full incident report explaining the CRL URL fields were empty because no certificates were issued, stating this was not noncompliance with Section 6.2, and describing the CCADB updates that cleared CRL Watch.
  5. Microsoft Corporation — Reported weekly status that action items were complete and closure reporting would follow.
  6. Microsoft Corporation — Submitted a report closure summary stating the CCADB records were updated with valid CRL URLs and internal guidance/procedures were updated.
  7. CCADB representative — Issued a final call for comments and noted the incident report would be closed around 2026-02-11.
  8. Microsoft Corporation — Noted the closure report had been submitted and requested closure if no further comments were provided.
Participants
Microsoft Corporation CCADB representative
Related Bugzilla IDs Mentioned
Similar Local Cases
#2021175 RESOLVED Ca Certificate Compliance Incident Opened 2026-03-05 · Closed 2026-04-03 · 100% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#2009543 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-09 · 100% similar
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
#2009542 RESOLVED Ca Certificate Compliance Incident Repository Issue Opened 2026-01-10 · Closed 2026-02-17 · 100% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
#2009539 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-17 · 99% similar
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
#2009541 RESOLVED Incident Opened 2026-01-10 · Closed 2026-02-11 · 97% similar
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
#1999850 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Revocation Issue Opened 2025-11-13 · Closed 2026-07-01 · 95% similar
Microsoft PKI Services: OCSP Non-Compliance
#2008847 RESOLVED Incident Opened 2026-01-06 · Closed 2026-02-17 · 95% similar
Microsoft PKI Services: Sample Site Certificates expired
#1970968 RESOLVED Ca Certificate Compliance Opened 2025-06-06 · Closed 2025-07-08 · 95% similar
Microsoft PKI Services: Incorrect Revocation Reason Code

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action