← Microsoft Corporation cases
Bugzilla #2032476
Certificate Misissuance
Microsoft PKI Services: Misissuance detected by PKIMetal
RESOLVED
INVALID
Microsoft Corporation
AI Summary
A third-party reporter flagged multiple end entity certificates issued by 'Microsoft Secure Server CA 2011' as having issues detected by PKIMetal. Microsoft clarified that these certificates are intended solely for Windows Operating System compatibility and are not part of the Microsoft Trusted Root Program (TRP). As such, they are not subject to the Baseline Requirements. Microsoft requested the case be closed as INVALID, asserting that no policies were violated.
Chronology
- Bug opened regarding misissuance.
- Microsoft clarified the status of the certificates.
- Final call for comments before closure.
- Bug closed as INVALID.
Participants
incident-reporting@ccadb.org
CentralPKI@microsoft.com
rdaurne77@gmail.com
hablutzel1@gmail.com
ekbugzilla@fastmail.com
certreporter@gmail.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
VISA: Misissuance detected by PKIMetal
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)
DigiCert: Misissuance detected by PKIMetal
Firmaprofesional: Misissuance of TLS Subordinate CA "AC Firmaprofesional - Secure Web 2024"
IdenTrust: Cross-signed root certificate mis-issuance
Microsoft PKI Services: Certificate Mis-Issuance, Locality Missing
Microsoft PKI Services: Certificate Mis-Issuance, DNSNames must have a valid TLD
Microsoft PKI Services: Certificate Mis-Issuance, DNSName is not FQDN, Preferred Name Syntax