Let's Encrypt: Non-BR-Compliant Certificate Issuance
This case concerns certificates issued by Let’s Encrypt (ISRG) that were reported as non-compliant with the CA/Browser Forum Baseline Requirements. The issue involved improper normalization of internationalized domain names (IDNs). The bug was filed after the incident was discussed in the mozilla.dev.security.policy forum, with Mozilla requesting that the CA respond in Bugzilla. Let’s Encrypt stated that it was made aware of the compliance issue at 11:30am PST on August 10, 2017 by a community member, and that a fix was applied to its production infrastructure the same day. The CA reported that the problematic code was introduced on October 20, 2016, that the last affected certificate was issued on August 10, 2017, and that it found 16 unexpired affected certificates in total. Let’s Encrypt also stated that the mistake was not caught during CA software code review and that the relevant RFCs are not easy to understand. The bug was resolved as FIXED.
- Problematic IDN normalization code was introduced into Let’s Encrypt systems.
- Let’s Encrypt was notified of an IDN normalization compliance issue and applied a production fix the same day.
- Mozilla representative — Requested that Let’s Encrypt respond in Bugzilla with details about how it became aware of the problems, confirmation it stopped issuing problematic certificates, affected certificate lists, remediation steps and timelines, and related explanations under the BR revocation expectations.
- Kflag representative — Provided the CA’s account of notification (community member at 11:30am PST on Aug 10, 2017), stated a same-day production fix, listed affected certificate fingerprints, reported 16 unexpired affected certificates, explained the mistake was missed during code review, and said the matter was resolved the day it was notified.