← Internet Security Research Group cases
Bugzilla #1627614 Delayed Revocation

Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

The case concerns Let's Encrypt’s revocation of certificates after receiving reports of key compromise. The reporter stated that between 2020-04-05 07:51:00 and 2020-04-05 07:51:21 UTC, 12 revocation requests were sent to c**********s@letsencrypt.org for 42 certificates and precertificates, and that the OCSP revocationTime values observed were 2020-04-06 08:19:09 or 2020-04-06 08:19:10—more than 24 hours after the reports were submitted. The reporter argued this violated the requirement to revoke within 24 hours when key compromise evidence is obtained. In response, a Let's Encrypt employee summarized that 12 subsequent key-compromise reports were received, and that investigation, revocation, and key blocking were performed 28 minutes after the 24-hour revocation deadline. They provided a timeline indicating that 24 serials associated with the reported compromised keys were found and revoked at 2020-04-06 08:19:00, and stated that the compromised keys were added to a blocklist to prevent future issuance using those keys. They also explained that an email went unanswered for 11 hours, triggering a secondary notification, and that the initial reports were discovered only after that secondary notification; they said they missed the deadline by 28 minutes and planned to add additional monitoring and alerting. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:15 UTC Confidence: 0.90 5 comments
Chronology
  1. Let's Encrypt received 12 emails reporting key compromise via c**********s@letsencrypt.org.
  2. Let's Encrypt found and revoked 24 serials associated with the reported compromised keys and added the compromised keys to a blocklist.
  3. Mozilla CA Program bug was created to report delayed revocation after key-compromise reports.
Thread Activity
  1. Hezmatt representative — Reported that OCSP revocationTime values for the affected certificates were observed more than 24 hours after the key-compromise reports were submitted.
  2. Community commenter — Asked whether the revocation time shown in the CRL or OCSP response alone was sufficient and noted the report did not indicate whether evidence of a failure to revoke was recorded.
  3. Hezmatt representative — Provided a table showing revocationTime and OCSP status transitions for the certificates around the revocation period.
  4. Internet Security Research Group — Submitted a summary and timeline stating that revocation and key blocking occurred 28 minutes after the 24-hour deadline, explained why the deadline was missed, and listed steps and tooling for handling key-compromise reports.
  5. Community commenter — Commented that Comment #3’s response appeared to indicate the timeline of changes was already implemented based on past-tense wording.
Participants
Hezmatt representative Community commenter Internet Security Research Group
Related Bugzilla IDs Mentioned
Similar Local Cases
#1625322 RESOLVED Delayed Revocation Opened 2020-03-26 · Closed 2023-02-22 · 100% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1639794 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 97% similar
Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
#1619179 RESOLVED Delayed Revocation Opened 2020-03-02 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Incomplete revocation for CAA rechecking bug
#1715672 RESOLVED Delayed Revocation Opened 2021-06-10 · Closed 2023-02-22 · 85% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1795483 RESOLVED Delayed Revocation Opened 2022-10-14 · Closed 2023-02-22 · 80% similar
Let's Encrypt: Delayed revocation for removed gTLD
#1799755 RESOLVED Delayed Revocation Opened 2022-11-08 · Closed 2024-05-09 · 80% similar
Let's Encrypt: End Entity CRLs Not Reissued On Time
#1639801 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 79% similar
DigiCert: Failure to revoke key-compromised certificates within 24 hours
#1639802 RESOLVED Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 79% similar
DigiCert: Failure to revoke key-compromised certificate

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action