← Internet Security Research Group cases
Bugzilla #1627614
Certificate Problem Report
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
RESOLVED
FIXED
Internet Security Research Group
AI Summary
This case addresses Let's Encrypt's failure to revoke certificates that were reported as compromised within the required 24-hour timeframe. A total of 12 revocation requests were submitted on April 5, 2020, but the revocations were processed 28 minutes past the deadline. The CA acknowledged the issue and has since implemented changes to improve their response to key compromise reports, including better monitoring and alerting mechanisms.
Chronology
- 12 emails reporting key compromise sent to Let's Encrypt
- Certificates were revoked 28 minutes after the 24-hour deadline
Participants
Josh Aas
Matt Palmer
Ryan Sleevi
A. Gabbitas
External References
Similar Local Cases
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
Let's Encrypt: certificate lifetimes 90 days plus one second
Let's Encrypt: Incomplete revocation for CAA rechecking bug
DigiCert: Failure to revoke key-compromised certificates within 24 hours
Sectigo: Failure to revoke key-compromised certificates
GoDaddy: Failure to revoke certificate with compromised key within 24 hours
DigiCert: Failure to revoke key-compromised certificate
Sectigo: Failure to provide a preliminary report within 24 hours