← Internet Security Research Group cases
Bugzilla #1391867 Ca Certificate Compliance Certificate Misissuance

Let's Encrypt: Non-BR-Compliant Certificate Issuance

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns certificates issued by Let’s Encrypt (ISRG) that were reported as non-compliant with the CA/Browser Forum Baseline Requirements. The issue involved improper normalization of internationalized domain names (IDNs). The bug was filed after the incident was discussed in the mozilla.dev.security.policy forum, with Mozilla requesting that the CA respond in Bugzilla. Let’s Encrypt stated that it was made aware of the compliance issue at 11:30am PST on August 10, 2017 by a community member, and that a fix was applied to its production infrastructure the same day. The CA reported that the problematic code was introduced on October 20, 2016, that the last affected certificate was issued on August 10, 2017, and that it found 16 unexpired affected certificates in total. Let’s Encrypt also stated that the mistake was not caught during CA software code review and that the relevant RFCs are not easy to understand. The bug was resolved as FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 11:59 UTC Revised: 2026-06-16 19:10 UTC Confidence: 0.86 2 comments
Chronology
  1. Problematic IDN normalization code was introduced into Let’s Encrypt systems.
  2. Let’s Encrypt was notified of an IDN normalization compliance issue and applied a production fix the same day.
Thread Activity
  1. Mozilla representative — Requested that Let’s Encrypt respond in Bugzilla with details about how it became aware of the problems, confirmation it stopped issuing problematic certificates, affected certificate lists, remediation steps and timelines, and related explanations under the BR revocation expectations.
  2. Kflag representative — Provided the CA’s account of notification (community member at 11:30am PST on Aug 10, 2017), stated a same-day production fix, listed affected certificate fingerprints, reported 16 unexpired affected certificates, explained the mistake was missed during code review, and said the matter was resolved the day it was notified.
Participants
Mozilla representative Kflag representative
Similar Local Cases
#1735247 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2021-10-11 · Closed 2023-02-22 · 91% similar
Let's Encrypt: Mis-issued certificates related to SC48v2
#1319609 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2016-11-23 · Closed 2023-02-22 · 90% similar
Let's Encrypt: certs issued contrary to CPS due to incomplete blocklist
#1398427 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2017-09-09 · Closed 2023-02-22 · 90% similar
Let's Encrypt: CAA Misissuances
#1462735 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2018-05-18 · Closed 2023-02-22 · 89% similar
Let's Encrypt: Case-sensitive CAA tag processing
#1789521 RESOLVED Certificate Misissuance Opened 2022-09-06 · Closed 2024-05-09 · 81% similar
Let's Encrypt: Certificates issued to Elliptic Curve Debian Weak Keys
#1966515 RESOLVED Certificate Misissuance Opened 2025-05-14 · Closed 2025-06-04 · 81% similar
Let's Encrypt: Issuance for Invalid Internationalized Domain Name
#1838667 RESOLVED Certificate Misissuance Opened 2023-06-15 · Closed 2023-07-05 · 79% similar
Let's Encrypt: Duplicate Serial Numbers
#1586792 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-10-07 · Closed 2023-02-22 · 72% similar
QuoVadis: Issuance of intermediates after 2019-01-01 that do not comply with Mozilla Policy or the BRs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action