← Internet Security Research Group cases
Bugzilla #1577652 Self Reported Incident Revocation Issue

Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates

RESOLVED INVALID Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let's Encrypt identified an issue where their OCSP responder returned 'unauthorized' for some precertificates due to a design flaw in their Boulder code. This was discovered after reviewing a related bug report from Apple. In response, Let's Encrypt implemented a plan to verify OCSP responses for all precertificates and configured alerts for the conditions that caused the issue. They deployed a code change to address the problem but later reverted it due to a higher incidence of timeouts affecting precertificate handling. They continue to monitor and manually generate OCSP responses as needed. The case has been resolved as invalid.

Model: gpt-4o-mini Generated: 2026-06-13 19:34 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.85 16 comments
Chronology
  1. Incident began after Let's Encrypt reviewed a related bug report.
  2. Let's Encrypt deployed a code change to Boulder.
  3. Let's Encrypt reverted the code change due to higher timeout issues.
Thread Activity
  1. Internet Security Research Group — Let's Encrypt discovered OCSP issues for 35 precertificates and outlined steps for remediation.
  2. Internet Security Research Group — Confirmed deployment of the code change to address OCSP issues.
  3. Internet Security Research Group — Provided a detailed incident report outlining the timeline and actions taken.
  4. Fastly representative — Resolved the incident as INVALID after review.
Participants
Internet Security Research Group Community commenter Primekey representative Fastly representative
Similar Local Cases
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 98% similar
Let's Encrypt: CAA Rechecking bug
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 94% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1486650 RESOLVED Self Reported Incident Revocation Issue Opened 2018-08-27 · Closed 2023-02-22 · 91% similar
Let's Encrypt: OCSP "unauthorized" responses
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 90% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1576789 RESOLVED Self Reported Incident Validation Issue Opened 2019-08-27 · Closed 2024-05-09 · 87% similar
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 86% similar
Let's Encrypt: Improper encoding of wildcard certificates
#1972745 RESOLVED Self Reported Incident Opened 2025-06-18 · Closed 2025-07-30 · 86% similar
Let's Encrypt: Deployed Unreviewed Boulder Code
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 84% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action