← Internet Security Research Group cases
Bugzilla #1319609
Certificate Misissuance
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
RESOLVED
Internet Security Research Group
AI Summary
This case addresses a misissuance of certificates by Let's Encrypt due to an incomplete blocklist caused by a bug in their issuance script. The issue was identified and resolved, with all affected certificates revoked. The incident highlighted the importance of compliance with the Certification Practice Statement (CPS) and the need for improved testing and policy review. Mozilla has determined that no further action is necessary as the CA has taken appropriate steps to rectify the situation.
Chronology
- Problem with issuance blocklist identified and fixed.
- Case resolved with all affected certificates revoked.
Participants
Kathleen Wilson
Gervase Markham
jaas@kflag.net
External References
Similar Local Cases
Let's Encrypt: CAA Misissuances
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
SwissSign: Two certs issued with same issuer and serial number
DigiCert / Inteso San Paulo: Double dot characters
StartCom StartEncrypt vulnerability allowed issuance of fraudulent google.com, dropbox.com, etc certificates
Actalis: Certs issued with same issuer and serial number
Camerfirma: Certs issued with same issuer and serial number
Certinomis: Cross-signing of StartCom intermediate certs, and delay in reporting it in CCADB