← Microsoft Corporation cases
Bugzilla #2009545
Certificate Problem Report
Microsoft PKI Services: Improper Disclosure of CRLs – Protocol Scheme
RESOLVED
FIXED
Microsoft Corporation
AI Summary
Microsoft PKI Services (MPS) identified additional syntax issues with the Certificate Revocation List (CRL) URLs posted in the CCADB during an investigation into improper CRL disclosures. Although the CRL URLs were left empty because no certificates had been issued, this led to flags in the CRL Watch tool for unsupported protocol schemes. MPS updated the CCADB entries with valid CRL URLs and improved internal processes to ensure compliance with CCADB guidance. The incident was resolved without any ongoing commitments, confirming that MPS was compliant with CCADB policy requirements.
Chronology
- MPS created six CA.
- MPS became aware of a CRL Watch flag.
- MPS updated CCADB with the full CRLs.
Participants
CentralPKI@microsoft.com
External References
Similar Local Cases
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – Existing CAs
Microsoft PKI Services: Improper Disclosure of CRLs – Does Not Match CA Subject
Microsoft PKI Services: Improper Disclosure of CRL
Microsoft PKI Services: Improper Disclosure of CRLs – IDP – New CAs
Microsoft PKI Services: Sample Site Certificates expired
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
Microsoft PKI Services: Failure to report within 72 hrs - Sample Site Certs Expired
Microsoft PKI Services: Failure to Revoke in 5 Days for 1962829