← Internet Security Research Group cases
Bugzilla #1486650 Self Reported Incident Revocation Issue

Let's Encrypt: OCSP "unauthorized" responses

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case reports an incident involving Let’s Encrypt’s OCSP responder service. On 2018-08-23, a configuration change deployed to the OCSP responder resulted in about 90% of traffic to the origin receiving OCSP "unauthorized" statuses for valid OCSP requests. The change was reverted the same day, but cached OCSP responses at the CDN could have caused affected statuses to be served for a limited period after resolution. The incident was attributed to a bug in the OCSP request validation implementation that improperly rejected OCSP requests unless they matched the last configured serial prefix rather than any configured serial prefix; the underlying implementation issue was later fixed. The CA reported the incident and described remediation steps, including reviewing monitoring procedures to ensure monitoring parity between production and staging, extending OCSP monitoring to include OCSP statuses (including "unauthorized"), and adding alerts for unusually high fractions of unauthorized or revoked OCSP responses. The CA stated that these remediation items were completed and considered the remediation for the incident complete. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 17:54 UTC Revised: 2026-06-16 19:13 UTC Confidence: 0.86 3 comments
Chronology
  1. Let’s Encrypt deployed an OCSP responder configuration change that caused many valid OCSP requests to receive OCSP "unauthorized" statuses.
  2. Let’s Encrypt reverted the OCSP responder configuration change to resolve the issue.
  3. Let’s Encrypt disclosed the OCSP incident and remediation details in the Mozilla CA Program bug.
  4. Let’s Encrypt reported completion of the listed remediation items and stated remediation was complete.
Thread Activity
  1. Fastly representative — Wayne Thayer posted an incident report describing the OCSP "unauthorized" status problem, the cause, the revert, and three remediation items.
  2. Kflag representative — Josh Aas asked to update the bug as remediation items were completed.
  3. Fastly representative — Wayne Thayer reported that monitoring parity was applied to staging, OCSP status monitoring was extended (with a referenced Boulder change), and alerts for unauthorized/revoked fractions were added, and stated remediation was complete.
Participants
Fastly representative Kflag representative
Similar Local Cases
#1577652 RESOLVED Self Reported Incident Revocation Issue Opened 2019-08-29 · Closed 2022-11-14 · 91% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 90% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1576789 RESOLVED Self Reported Incident Validation Issue Opened 2019-08-27 · Closed 2024-05-09 · 82% similar
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 82% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 81% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1972745 RESOLVED Self Reported Incident Opened 2025-06-18 · Closed 2025-07-30 · 81% similar
Let's Encrypt: Deployed Unreviewed Boulder Code
#1645276 RESOLVED Self Reported Incident Opened 2020-06-12 · Closed 2023-02-22 · 81% similar
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 80% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action