Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours
This case concerns Let's Encrypt's failure to revoke a certificate associated with a compromised private key within the required 24-hour timeframe. The issue was triggered by a certificate problem report received on May 5, 2020, which indicated that a private key had been compromised. Although Let's Encrypt staff processed the report within 24 hours, a procedural error led to a delay in the actual revocation, which occurred 37 hours and 21 minutes after the report was filed. Let's Encrypt has since implemented changes to their revocation procedures to prevent similar incidents in the future, including automation of key blocking and revocation processes.
- Certificate problem report received regarding a compromised private key.
- Certificate associated with the compromised key was revoked.
- Hezmatt representative — Reported the failure to revoke the compromised certificate within 24 hours.
- Internet Security Research Group — Provided a summary of the incident and the timeline of actions taken.
- Mozilla representative — Reviewed the incident report and indicated the bug could be closed.
- Internet Security Research Group — Confirmed that changes to the CPS were made to clarify reporting procedures.
- Mozilla representative — Expressed satisfaction with the revisions made by Let's Encrypt.