Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
Let's Encrypt identified an issue where their OCSP responder returned 'unauthorized' for some precertificates due to a design flaw in their Boulder code. This was discovered after reviewing a related bug report from Apple. In response, Let's Encrypt implemented a plan to verify OCSP responses for all precertificates and configured alerts for the conditions that caused the issue. They deployed a code change to address the problem but later reverted it due to a higher incidence of timeouts affecting precertificate handling. They continue to monitor and manually generate OCSP responses as needed. The case has been resolved as invalid.
- Incident began after Let's Encrypt reviewed a related bug report.
- Let's Encrypt deployed a code change to Boulder.
- Let's Encrypt reverted the code change due to higher timeout issues.
- Internet Security Research Group — Let's Encrypt discovered OCSP issues for 35 precertificates and outlined steps for remediation.
- Internet Security Research Group — Confirmed deployment of the code change to address OCSP issues.
- Internet Security Research Group — Provided a detailed incident report outlining the timeline and actions taken.
- Fastly representative — Resolved the incident as INVALID after review.