← Internet Security Research Group cases
Bugzilla #1619179 Delayed Revocation

Let's Encrypt: Incomplete revocation for CAA rechecking bug

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Let's Encrypt reported a bug related to incomplete revocation due to a CAA rechecking issue. After discovering the bug on February 29, 2020, they announced plans to revoke approximately 3 million potentially affected certificates. They successfully revoked 1.7 million certificates by the compliance deadline but decided not to revoke over 1 million certificates to avoid significant disruption to web services. Let's Encrypt committed to a plan for ongoing revocation of remaining certificates as they are replaced, with all affected certificates either revoked or expired by May 29, 2020. The case is now resolved.

Model: gpt-4o-mini Generated: 2026-06-13 21:11 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.85 21 comments
Chronology
  1. Let's Encrypt discovered a bug in their CAA checking code.
  2. Let's Encrypt revoked 1,711,396 certificates by the compliance deadline.
  3. All affected certificates have expired or been revoked.
Thread Activity
  1. Kflag representative — Let's Encrypt reported the bug and outlined their revocation plan.
  2. Fastly representative — Mozilla emphasized that exceptions to revocation requirements are not granted.
  3. Kflag representative — Let's Encrypt provided an update on the revocation progress.
  4. Fastly representative — It was confirmed that all questions have been answered and remediation is complete.
Participants
Kflag representative Fastly representative Community commenter Internet Security Research Group
External References
Similar Local Cases
#1625322 RESOLVED Delayed Revocation Opened 2020-03-26 · Closed 2023-02-22 · 100% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1715672 RESOLVED Delayed Revocation Opened 2021-06-10 · Closed 2023-02-22 · 96% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1627614 RESOLVED Delayed Revocation Opened 2020-04-06 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1639794 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 86% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1795483 RESOLVED Delayed Revocation Opened 2022-10-14 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Delayed revocation for removed gTLD
#1799755 RESOLVED Delayed Revocation Opened 2022-11-08 · Closed 2024-05-09 · 79% similar
Let's Encrypt: End Entity CRLs Not Reissued On Time
#1580525 RESOLVED Delayed Revocation Opened 2019-09-11 · Closed 2023-02-22 · 76% similar
D-TRUST: Delayed revocation of EV certificates
#1595113 RESOLVED Delayed Revocation Opened 2019-11-08 · Closed 2023-02-22 · 76% similar
Buypass: Intermediate certificates not listed in audit reports

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action