← Internet Security Research Group cases
Bugzilla #1625322
Certificate Problem Report
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
RESOLVED
FIXED
Internet Security Research Group
AI Summary
This case addresses the failure of Let's Encrypt to revoke certificates that were compromised within the required 24-hour timeframe. The issue was reported by Matt Palmer, highlighting that two certificates remained unrevoked despite the revocation of others using the same private key. Let's Encrypt acknowledged the oversight and outlined steps to improve their processes, including implementing automated key blocking and revocation via their API. The situation has since been resolved, with affected certificates revoked and measures put in place to prevent future occurrences.
Chronology
- Incident reported by Matt Palmer.
- Let's Encrypt blocked issuance for the two compromised keys.
- Automated key blocking and revocation implemented.
Participants
Ryan Sleevi
Josh Aas
Matt Palmer
Andrew Gabbitas
External References
Similar Local Cases
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: Incomplete revocation for CAA rechecking bug
Let's Encrypt: certificate lifetimes 90 days plus one second
DigiCert: Failure to revoke key-compromised certificate
DigiCert: Failure to revoke key-compromised certificates within 24 hours
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
Let's Encrypt: Expired ISRG Root OCSP X1 Certificate