← Internet Security Research Group cases
Bugzilla #1319609 Ca Certificate Compliance Certificate Misissuance

Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case describes an issuance blocklist problem at Let’s Encrypt that caused the CA to issue certificates contrary to its CPS. Mozilla was informed that between 11:30am and 4pm Pacific on November 21, 2016, a bug in the blocklist assembly script was identified, confirmed, and fixed; the script incorrectly and silently failed to process a small number of blocklist entries. Let’s Encrypt staff worked to identify all domains/blocks that had failed to propagate and any certificates issued for those domains. The thread lists several certificates found to have been mis-issued by policy (including certificates for gov.ir, gov.sy, and .mil), and states that all unexpired certificates were revoked and account contacts were notified. Mozilla’s representative discussed that the concern was compliance with CP/CPS and noted that revocation had been performed. Later, Let’s Encrypt stated that the buggy code/script had been deleted and the blacklist is now a static text document, and Mozilla indicated the issue was dealt with to its satisfaction.

Model: gpt-5.4-nano Generated: 2026-06-13 11:59 UTC Revised: 2026-06-16 19:09 UTC Confidence: 0.86 5 comments
Chronology
  1. Let’s Encrypt identified and fixed a bug in its blocklist assembly script that caused incomplete blocklist propagation.
  2. A Mozilla CA Program compliance bug was filed describing the misissuance-by-policy incident and listing affected certificates.
  3. Let’s Encrypt reported the buggy script was deleted and the blacklist process changed to a static document; Mozilla closed the matter to its satisfaction.
Thread Activity
  1. Mozilla representative — Reported that a blocklist script bug caused some blocklist entries not to propagate, leading to certificates issued contrary to CPS/CP, and stated affected certificates were identified and all unexpired certificates were revoked with account contacts notified.
  2. Mozilla representative — Discussed Mozilla’s concern as CP/CPS compliance and stated that, given revocation, no further action was necessary at that time.
  3. Kflag representative — Provided CPS/CP context for why some domains (e.g., .mil) are called out while others (e.g., gov.ir/gov.sy) are not explicitly listed.
  4. Kflag representative — Stated the buggy script was deleted and the blacklist is now a static text document, and asked for an update on progress toward closing the issue.
  5. Mozilla representative — Indicated the issue had been dealt with to Mozilla’s satisfaction.
Participants
Mozilla representative Kflag representative
Similar Local Cases
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 100% similar
Let's Encrypt: CAA Misissuances
#1462735 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 97% similar
Let's Encrypt: Case-sensitive CAA tag processing
#1391867 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-08-19 · Closed 2023-02-22 · 90% similar
Let's Encrypt: Non-BR-Compliant Certificate Issuance
#1735247 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-11 · Closed 2023-02-22 · 88% similar
Let's Encrypt: Mis-issued certificates related to SC48v2
#1369359 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-06-01 · Closed 2023-02-22 · 86% similar
StartCom: mis-issuance of certs with unvalidated domain names and bogus field values
#1313873 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-10-29 · Closed 2022-11-14 · 84% similar
SHA-1 issuance by DocuSign root
#1789521 RESOLVED Certificate Misissuance Opened 2022-09-06 · Closed 2024-05-09 · 79% similar
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 79% similar
Let's Encrypt: Duplicate Serial Numbers

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action