Let's Encrypt: Incomplete revocation for CAA rechecking bug
Let's Encrypt reported a bug related to incomplete revocation due to a CAA rechecking issue. After discovering the bug on February 29, 2020, they announced plans to revoke approximately 3 million potentially affected certificates. They successfully revoked 1.7 million certificates by the compliance deadline but decided not to revoke over 1 million certificates to avoid significant disruption to web services. Let's Encrypt committed to a plan for ongoing revocation of remaining certificates as they are replaced, with all affected certificates either revoked or expired by May 29, 2020. The case is now resolved.
- Let's Encrypt discovered a bug in their CAA checking code.
- Let's Encrypt revoked 1,711,396 certificates by the compliance deadline.
- All affected certificates have expired or been revoked.
- Kflag representative — Let's Encrypt reported the bug and outlined their revocation plan.
- Fastly representative — Mozilla emphasized that exceptions to revocation requirements are not granted.
- Kflag representative — Let's Encrypt provided an update on the revocation progress.
- Fastly representative — It was confirmed that all questions have been answered and remediation is complete.