Let's Encrypt: Expired ISRG Root OCSP X1 Certificate
This case describes an incident where a delegated OCSP signing certificate issued for ISRG Root X1 expired on 2020-06-04 and was reissued on 2020-06-09. During the period it was expired but not replaced, TLS clients building chains to ISRG Root X1 experienced OCSP validation errors when validating the OCSP signing certificate. The incident was reported to Let's Encrypt after security officers received an encrypted email from Fudo Security on 2020-06-08. Let's Encrypt staff coordinated datacenter access, prepared a key ceremony, completed it on 2020-06-09, and began serving new OCSP responses; the incident was marked resolved after new OCSP responses were generated and served. The bug was later updated to confirm that remaining remediation items listed in Comment #1 were deployed as of 2020-08-06, and Mozilla indicated an inclination to close the bug as fixed on or about 13-Aug-2020. The bug’s resolution is FIXED and the current status is RESOLVED.
- The delegated OCSP signing certificate for ISRG Root X1 expired.
- Let's Encrypt completed a key ceremony and began serving new OCSP responses after reissuing the delegated OCSP signing certificate.
- Mozilla was told that remaining remediation items from the incident report had been deployed.
- Internet Security Research Group — Opened the incident report describing the expired delegated OCSP signing certificate, its impact, and the remediation timeline, and provided a related certificate URL.
- Mozilla representative — Asked whether all fixes listed in Comment #1 had been deployed.
- Internet Security Research Group — Confirmed that, as of 2020-08-06, the remaining remediation items from the bug had been deployed and referenced the bug’s Comment #1.
- Mozilla representative — Indicated an inclination to close the bug as fixed on or about 13-Aug-2020 unless additional concerns were raised.