← Internet Security Research Group cases
Bugzilla #1576789
Certificate Problem Report
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
RESOLVED
FIXED
Internet Security Research Group
AI Summary
On August 20, 2019, Let's Encrypt received a report regarding incorrect OCSP responses due to a bug in their CDN provider, Akamai. The issue arose when OCSP requests were made with a specific header, leading to valid but incorrect responses. After identifying the problem, Let's Encrypt worked with Akamai to implement a temporary workaround and subsequently confirmed a permanent fix. The incident did not affect the integrity of certificate issuance, and no problematic certificates were issued.
Chronology
- Initial report received from community member
- Ticket filed with Akamai
- Temporary workaround applied
- Private disclosures made to root programs
- Akamai confirms global permanent fix
Participants
Josh Aas
Stefan Eissing
W. Thayer
External References
Similar Local Cases
Let's Encrypt: Incomplete revocation for CAA rechecking bug
Let's Encrypt: Non-BR-Compliant Certificate Issuance
Let's Encrypt: Case-sensitive CAA tag processing
Let's Encrypt: certificate lifetimes 90 days plus one second
Let's Encrypt: OCSP "unauthorized" responses
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
Let's Encrypt: Improper encoding of wildcard certificates
Let's Encrypt: No Meaningful Subject Distinguished Name