← Internet Security Research Group cases
Bugzilla #1577652
Certificate Problem Report
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
RESOLVED
INVALID
Internet Security Research Group
AI Summary
Let's Encrypt identified an issue where their OCSP responder returned 'unauthorized' for some precertificates due to a design flaw in their Boulder code. This occurred when a precertificate was issued, but the corresponding certificate was not issued due to an error. The team took steps to ensure that OCSP responses were correctly served for valid precertificates and implemented monitoring to address any future occurrences. The issue was resolved, and a code change was deployed to prevent similar problems.
Chronology
- Incident began after reading a related bug report.
- Code change deployed to address the issue.
- Code change reverted due to unexpected issues.
- Boulder fix redeployed.
Participants
Jacob Hoffman-Andrews
Ryan Sleevi
Tomas
W. Thayer
External References
Similar Local Cases
Let's Encrypt: Incomplete revocation for CAA rechecking bug
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: OCSP responses with no revocationReason
Let's Encrypt: certificate lifetimes 90 days plus one second
Let's Encrypt: 302 total OCSP responses available beyond acceptable timelines
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: CAA Rechecking bug
SECOM: certificate for which “OU=-”