← Internet Security Research Group cases
Bugzilla #1639794 Delayed Revocation

Let's Encrypt: Failure to revoke key-compromised certificate within 24 hours

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case concerns Let's Encrypt's failure to revoke a certificate associated with a compromised private key within the required 24-hour timeframe. The issue was triggered by a certificate problem report received on May 5, 2020, which indicated that a private key had been compromised. Although Let's Encrypt staff processed the report within 24 hours, a procedural error led to a delay in the actual revocation, which occurred 37 hours and 21 minutes after the report was filed. Let's Encrypt has since implemented changes to their revocation procedures to prevent similar incidents in the future, including automation of key blocking and revocation processes.

Model: gpt-4o-mini Generated: 2026-06-13 21:12 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.85 13 comments
Chronology
  1. Certificate problem report received regarding a compromised private key.
  2. Certificate associated with the compromised key was revoked.
Thread Activity
  1. Hezmatt representative — Reported the failure to revoke the compromised certificate within 24 hours.
  2. Internet Security Research Group — Provided a summary of the incident and the timeline of actions taken.
  3. Mozilla representative — Reviewed the incident report and indicated the bug could be closed.
  4. Internet Security Research Group — Confirmed that changes to the CPS were made to clarify reporting procedures.
  5. Mozilla representative — Expressed satisfaction with the revisions made by Let's Encrypt.
Participants
Hezmatt representative Internet Security Research Group Mozilla representative
External References
Similar Local Cases
#1625322 RESOLVED Delayed Revocation Opened 2020-03-26 · Closed 2023-02-22 · 97% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1627614 RESOLVED Delayed Revocation Opened 2020-04-06 · Closed 2023-02-22 · 97% similar
Let's Encrypt: Failure to revoke key-compromised certificates within 24 hours
#1715672 RESOLVED Delayed Revocation Opened 2021-06-10 · Closed 2023-02-22 · 95% similar
Let's Encrypt: Failure to revoke for Certificate Lifetime Incident
#1795483 RESOLVED Delayed Revocation Opened 2022-10-14 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Delayed revocation for removed gTLD
#1619179 RESOLVED Delayed Revocation Opened 2020-03-02 · Closed 2023-02-22 · 86% similar
Let's Encrypt: Incomplete revocation for CAA rechecking bug
#1799755 RESOLVED Delayed Revocation Opened 2022-11-08 · Closed 2024-05-09 · 86% similar
Let's Encrypt: End Entity CRLs Not Reissued On Time
#1639804 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 79% similar
Sectigo: Failure to revoke key-compromised certificate within 24 hours
#1639805 RESOLVED Revocation Issue Delayed Revocation Opened 2020-05-21 · Closed 2023-02-22 · 79% similar
Sectigo: Failure to revoke key-compromised certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action