← Internet Security Research Group cases
Bugzilla #1619047 Self Reported Incident Certificate Misissuance

Let's Encrypt: CAA Rechecking bug

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let's Encrypt identified a bug in their CAA code that caused incorrect validation of CAA records during certificate issuance. The issue was discovered on February 29, 2020, leading to a halt in certificate issuance shortly after confirmation. A fix was deployed the same day, and issuance was re-enabled. The bug allowed certificates to be issued even if CAA records later prohibited issuance, affecting over 3 million certificates. Let's Encrypt committed to a detailed investigation and provided a postmortem report outlining the timeline and actions taken in response to the incident.

Model: gpt-4o-mini Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:14 UTC Confidence: 0.90 16 comments
Chronology
  1. Let's Encrypt discovered a bug in their CAA code.
  2. Issuance of certificates was halted.
  3. A fix was deployed and issuance was re-enabled.
Thread Activity
  1. Internet Security Research Group — Confirmed the bug and halted issuance.
  2. Internet Security Research Group — Provided an incident report detailing the discovery and response timeline.
  3. Internet Security Research Group — Requested closure of the bug as all remediation items were completed.
Participants
Internet Security Research Group Community commenter Mozilla representative
Similar Local Cases
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 100% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 99% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1577652 RESOLVED Self Reported Incident Revocation Issue Opened 2019-08-29 · Closed 2022-11-14 · 98% similar
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 97% similar
Let's Encrypt: Early CRL Removal Incident
#1751984 RESOLVED Incident Self Reported Incident Opened 2022-01-25 · Closed 2023-02-22 · 95% similar
Let's Encrypt: TLS Using ALPN TLS Version and OID
#1921573 RESOLVED Self Reported Incident Policy Document Issue Opened 2024-09-27 · Closed 2024-11-06 · 92% similar
Let's Encrypt: No Meaningful Subject Distinguished Name
#1708834 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-30 · Closed 2023-02-22 · 90% similar
GlobalSign: Invalid stateOrProvinceName and locality pair
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 89% similar
Let's Encrypt: Incomplete and Inconsistent CRLs

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action