Microsoft PKI Services: Misissuance detected by PKIMetal
A third-party reporter flagged multiple end entity certificates issued by 'Microsoft Secure Server CA 2011' as having issues detected by PKIMetal. Microsoft PKI Services clarified that these certificates are intended solely for Windows Operating System compatibility and are not part of the Microsoft Trusted Root Program (TRP). They requested the bug be closed as INVALID, asserting that no policies or requirements were violated. The incident was discussed in relation to a broader context of compliance with the CA/B Forum Guidelines and CCADB Guidelines. The case was ultimately resolved with a request for closure as INVALID.
- Bug opened regarding misissuance of certificates
- Bug closed as INVALID
- CCADB representative — Reported multiple certificates with invalid domain name syntax.
- Microsoft Corporation — Clarified that the certificates are not publicly trusted and do not meet the definition of an incident.
- Microsoft Corporation — Requested closure of the bug as INVALID.
- CCADB representative — Final call for comments before closing the bug as INVALID.