← Internet Security Research Group cases
Bugzilla #1619179
Certificate Problem Report
Let's Encrypt: Incomplete revocation for CAA rechecking bug
RESOLVED
FIXED
Internet Security Research Group
AI Summary
Let's Encrypt encountered a bug related to CAA rechecking that led to incomplete revocation of certificates. After identifying the issue, they quickly deployed a fix and communicated the situation publicly. Although they planned to revoke approximately 3 million certificates, they determined that mass revocation could cause significant disruption. Ultimately, they revoked over 2 million certificates while allowing others to expire naturally, citing the need to minimize impact on users and the web ecosystem.
Chronology
- Identified bug in CAA checking code.
- Revocation deadline; over 2 million certificates revoked.
- All affected certificates expired or were revoked.
Participants
Josh Aas
W. Thayer
M. Nordhoff
Ryan Sleevi
Jacob Hoffman-Andrews
External References
Similar Local Cases
Let's Encrypt: OCSP Responder Returned "Unauthorized" for Some Precertificates
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: OCSP responses with no revocationReason
Let's Encrypt: certificate lifetimes 90 days plus one second
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: 2019.08.20 Incident: Incorrect OCSP responses under certain conditions
Let's Encrypt: CAA Rechecking bug