← Internet Security Research Group cases
Bugzilla #1446080 Ca Certificate Compliance Self Reported Incident

Let's Encrypt: Improper encoding of wildcard certificates

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an incident report by Let's Encrypt (operations team) about six test wildcard certificates issued under its publicly trusted root during final tests for general availability of wildcard certificate support. The certificates had a subject common name containing a “*.” label encoded as an ASN.1 PrintableString, which does not allow the asterisk character and violates RFC 5280. The issue was discovered via crt.sh linter flagging on 2018-03-13, and all six certificates were revoked. The root cause was identified as a Go language bug, which was resolved in Go v1.10, and Let's Encrypt stated it would resolve the issue by upgrading to Go v1.10 before proceeding with wildcard certificate launch plans. The thread also records an action item to integrate GlobalSign’s certlint and/or zlint into the existing cert-checker pipeline. The work to integrate certlint was completed and merged into testing on March 15, and the reporter later marked the bug resolved, stating that all actions had been completed.

Model: gpt-5.4-nano Generated: 2026-06-13 17:45 UTC Revised: 2026-06-16 19:12 UTC Confidence: 0.90 4 comments
Chronology
  1. Let's Encrypt became aware of improper wildcard certificate encoding via crt.sh linter flagging.
  2. Let's Encrypt revoked the six test wildcard certificates and completed integration of certlint into its testing pipeline.
  3. The bug was marked resolved after confirming actions were completed.
Thread Activity
  1. Fastly representative — Wayne Thayer reported that six test wildcard certificates were issued with an invalid ASN.1 PrintableString encoding for a “*.” label, noted the RFC 5280 violation, stated the certificates were revoked, and said the cause was a Go bug resolved in Go v1.10 with plans to upgrade and improve testing.
  2. Fastly representative — Wayne Thayer relayed an action item to integrate GlobalSign’s certlint and/or zlint into the cert-checker pipeline and asked for a completion date.
  3. Kflag representative — Josh Aas stated the certlint integration work was completed and merged into testing on March 15, with a link to the Boulder pull request.
  4. Fastly representative — Wayne Thayer marked the bug resolved, stating it appeared all actions were completed.
Participants
Fastly representative Kflag representative
Similar Local Cases
#1576789 RESOLVED Self Reported Incident Validation Issue Opened 2019-08-27 · Closed 2024-05-09 · 94% similar
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 88% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 87% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1577652 RESOLVED Self Reported Incident Revocation Issue Opened 2019-08-29 · Closed 2022-11-14 · 86% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 86% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 82% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 81% similar
Let's Encrypt: CAA Rechecking bug
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 81% similar
Let's Encrypt: Early CRL Removal Incident

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action