← Microsoft Corporation cases
Bugzilla #2034251
Self Incident Disclosure
Microsoft PKI Services: Failure to Update Full Incident Report within 14 days of discovering new root cause
RESOLVED
FIXED
Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update.
Always refer to the official Bugzilla thread as the authoritative source.
If you spot an inaccuracy, let me know via the contact form.
AI Summary
This case involves Microsoft PKI Services (MPS) failing to update their Full Incident Report (FIR) within 14 days after discovering a new root cause for delayed certificate revocation. A third-party report triggered the case, highlighting that MPS did not amend the FIR promptly after identifying additional delays. MPS acknowledged the oversight and has since updated their internal processes to ensure timely amendments to FIRs in the future. The case has been resolved, with MPS committing to a 14-day target for future updates.
Chronology
- MPS reported awareness of further delays in certificate revocation.
- MPS posted an amended FIR, 144 days after identifying the new root cause.
Thread Activity
- CentralPKI@microsoft.com — MPS acknowledged the failure to update the FIR within the required timeframe.
- CentralPKI@microsoft.com — MPS requested closure of the bug as invalid, citing no specific policy violation.
- CentralPKI@microsoft.com — MPS confirmed their commitment to amend FIRs more promptly in the future.
- bwilson@mozilla.com — Mozilla recommended closing the bug, noting MPS's commitment to improve procedures.
Participants
CentralPKI@microsoft.com
Zacharias.bjorngren@gmail.com
rdaurne77@gmail.com
bwilson@mozilla.com
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
Microsoft PKI Services: Failure to update action item status within 3 days
Microsoft PKI Services: Misissuance detected by PKIMetal
Microsoft PKI Services: Sample Site Certificates expired
Microsoft: improper disclosure of CRL
DigiCert: Threat of legal action to stifle Bugzilla discourse
Microsoft PKI Services: Subscriber certificate change made that was not compliant with CPS
Microsoft PKI Services: DV certificate issued with OV fields
Microsoft PKI Services: Policy Documentation, Failure to update Subscriber Certificate Max Validity Period