← Internet Security Research Group cases
Bugzilla #1645276 Self Reported Incident

Let's Encrypt: Expired ISRG Root OCSP X1 Certificate

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case describes an incident where a delegated OCSP signing certificate issued for ISRG Root X1 expired on 2020-06-04 and was reissued on 2020-06-09. During the period it was expired but not replaced, TLS clients building chains to ISRG Root X1 experienced OCSP validation errors when validating the OCSP signing certificate. The incident was reported to Let's Encrypt after security officers received an encrypted email from Fudo Security on 2020-06-08. Let's Encrypt staff coordinated datacenter access, prepared a key ceremony, completed it on 2020-06-09, and began serving new OCSP responses; the incident was marked resolved after new OCSP responses were generated and served. The bug was later updated to confirm that remaining remediation items listed in Comment #1 were deployed as of 2020-08-06, and Mozilla indicated an inclination to close the bug as fixed on or about 13-Aug-2020. The bug’s resolution is FIXED and the current status is RESOLVED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.86 5 comments
Chronology
  1. The delegated OCSP signing certificate for ISRG Root X1 expired.
  2. Let's Encrypt completed a key ceremony and began serving new OCSP responses after reissuing the delegated OCSP signing certificate.
  3. Mozilla was told that remaining remediation items from the incident report had been deployed.
Thread Activity
  1. Internet Security Research Group — Opened the incident report describing the expired delegated OCSP signing certificate, its impact, and the remediation timeline, and provided a related certificate URL.
  2. Mozilla representative — Asked whether all fixes listed in Comment #1 had been deployed.
  3. Internet Security Research Group — Confirmed that, as of 2020-08-06, the remaining remediation items from the bug had been deployed and referenced the bug’s Comment #1.
  4. Mozilla representative — Indicated an inclination to close the bug as fixed on or about 13-Aug-2020 unless additional concerns were raised.
Participants
Internet Security Research Group Mozilla representative
Similar Local Cases
#1753123 RESOLVED Revocation Issue Self Reported Incident Opened 2022-02-01 · Closed 2023-01-04 · 90% similar
Let's Encrypt: Failure to provide OCSP Responses for some certificates
#1752670 RESOLVED Certificate Misissuance Self Reported Incident Opened 2022-01-29 · Closed 2024-05-09 · 89% similar
Let's Encrypt: TLS Using ALPN Allows Additional Identifiers in Challenge Certificate
#1954861 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-03-18 · Closed 2025-04-09 · 89% similar
Let's Encrypt: Early CRL Removal Incident
#1742704 RESOLVED Incident Self Reported Incident Opened 2021-11-23 · Closed 2024-05-09 · 88% similar
Let's Encrypt: Potential Denial of Service against websites with broad private key reuse
#1619047 RESOLVED Self Reported Incident Certificate Misissuance Opened 2020-02-29 · Closed 2023-02-22 · 87% similar
Let's Encrypt: CAA Rechecking bug
#1715455 RESOLVED Self Reported Incident Opened 2021-06-09 · Closed 2024-01-10 · 87% similar
Let's Encrypt: certificate lifetimes 90 days plus one second
#1793114 RESOLVED Self Reported Incident Opened 2022-09-30 · Closed 2023-02-22 · 87% similar
Let's Encrypt: Incomplete and Inconsistent CRLs
#2038351 ASSIGNED Ca Certificate Compliance Incident Self Reported Incident Certificate Misissuance Opened 2026-05-08 Still Open · 86% similar
Let's Encrypt: Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action