← Internet Security Research Group cases
Bugzilla #1648840 Ca Certificate Compliance

Let's Encrypt: OCSP responses with no revocationReason

RESOLVED FIXED Internet Security Research Group
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case reports an issue where Let’s Encrypt OCSP responses for revoked certificates were served with revocationReason set to “unspecified” (0) after a short period, even though the certificates’ certStatus remained correctly set to revoked. Let’s Encrypt SRE noticed during routine maintenance on 2020-06-18 that an OCSP response for a certificate revoked with revocationReason = keyCompromise (1) was being served with revocationReason = unspecified (0). Let’s Encrypt identified the cause as a bug in code that updates OCSP responses: the initial OCSP response after revocation used the correct revocationReason, but updated responses used a default value instead of the value stored in the database. Let’s Encrypt stopped generating OCSP responses with the problem and fixed the code, with the fix merged and deployed on 2020-06-19. The bug was closed as RESOLVED with resolution FIXED, and Mozilla indicated it would be closed as Fixed rather than Invalid. Mozilla participants also stated they did not consider this a compliance incident, while acknowledging the usefulness of the proactive disclosure and explanation.

Model: gpt-5.4-nano Generated: 2026-06-13 21:13 UTC Revised: 2026-06-16 19:16 UTC Confidence: 0.86 4 comments
Chronology
  1. Let’s Encrypt SRE noticed during routine maintenance that OCSP responses for a revoked certificate were being served with revocationReason = unspecified despite certStatus remaining revoked.
  2. Let’s Encrypt deployed a fix to correct OCSP response revocationReason handling and stopped generating OCSP responses with the problem.
Thread Activity
  1. Internet Security Research Group — Created the bug report describing that after ~three days post-revocation, OCSP responses for revoked certificates with non-zero revocationReason were served with revocationReason = 0, due to an OCSP update code bug.
  2. Community commenter — Responded that it may not be a compliance bug under current policies, but praised the detailed proactive notification and asked if anything was missed.
  3. Internet Security Research Group — Agreed it likely does not violate CPS, and explained the notification was for unexpected unintended behavior and that public root-cause analysis helped prevent similar bugs.
  4. Mozilla representative — Stated Mozilla did not consider it a compliance incident and planned to close it as Fixed rather than Invalid, noting updates could still be posted after marking it fixed.
Participants
Internet Security Research Group Community commenter Mozilla representative
Similar Local Cases
#1684112 RESOLVED Ca Certificate Compliance Opened 2020-12-23 · Closed 2023-02-22 · 90% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
#1414039 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2017-11-02 · Closed 2024-05-09 · 80% similar
Let's Encrypt: Attacker-controlled google.tg certificate being used in the wild.
#1446080 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2018-03-15 · Closed 2023-02-22 · 79% similar
Let's Encrypt: Improper encoding of wildcard certificates
#1740493 RESOLVED Ca Certificate Compliance Certificate Misissuance Self Reported Incident Opened 2021-11-10 · Closed 2023-02-22 · 77% similar
Sectigo: Failure to block disallowed LDH labels in domain names
#1668007 RESOLVED Ca Certificate Compliance Opened 2020-09-29 · Closed 2023-02-22 · 77% similar
GlobalSign: Invalid stateOrProvinceName value
#1676440 RESOLVED Ca Certificate Compliance Self Reported Incident Opened 2020-11-10 · Closed 2023-02-22 · 77% similar
NetLock: Cumulative report connected to EV verification
#1559765 RESOLVED Ca Certificate Compliance Certificate Misissuance Opened 2019-06-17 · Closed 2023-02-22 · 77% similar
Izenpe: Multiple invalid EV certificates issued
#1662382 RESOLVED Ca Certificate Compliance Certificate Misissuance Closure Request Opened 2020-09-01 · Closed 2023-02-22 · 77% similar
GDCA: Incorrect Value in organizationName Field

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action